Central passwordless passkey: verify the assertion → SSO session (aal=2) + brand redirect URL

Authenticate every request with Authorization: Bearer <token> — a JWT or API token.

Download OpenAPI JSON