EPIC-02 auth shell
Recover access without weakening the record.
Password reset uses a single-use emailed link with a fifteen-minute lifetime. The token is prefilled from that link; local development can expose it only through the explicit loopback-only stub inspector.
Request reset token
Confirm reset
Resetting the account password also replaces its encrypted notebook key wrap. The saved phrase is therefore required, but never leaves this browser.
API target: /api/auth