/app/api/* still requires either the
navigator_session cookie from the OAuth flow at
/auth/login or a JWT bearer token — "Try it out" will prompt
you to sign in.
The MCP endpoint (/mcp, JSON-RPC over HTTP with a Google OAuth bearer
token) is out of scope for this document; MCP clients should consult the
MCP specification.