d0803019b5
- serve generates random UUID on startup - registration sends agentToken to gateway, stored in KV - gateway injects X-Agent-Token header when proxying to agent - serve rejects /api/* requests without valid token - healthz remains unauthenticated - tunnel URL is now protected — direct access returns 401 小橘 <xiaoju@shazhou.work>