Overview
OAuth 2.0 / OIDC identity providers + session lifecycle. Layers browser-based auth on top of the static bearer-token surface: bearer tokens continue to work byte-shape-identical; session tokens use the kgi_sk_* prefix so the same middleware routes both flavors. Providers are caller-plugged via IdentityProviderBinding (no baked-in list). Sessions persist via SessionStoreBinding. Code exchange is caller-supplied via exchangeCode. PKCE (S256) is mandatory. clientSecretRef is a REFERENCE — the plaintext secret never crosses the wire.