01
Two routes, no login
The counterparty surface is two token-authenticated routes. There is no account, no session and no auth library — the token in the link is the credential.
GET /f/••••••••••••••••••••••••
GET /s/••••••••••••••••••••••••
# no account · no session · token = credential