Central single-logout (browser) — revoke + clear the SSO cookie, then 302 back

Authenticate every request with Authorization: Bearer <token> — a JWT or API token.

Download OpenAPI JSON