Server wires the adapters (REST + GraphQL + MCP) over one Core and one auth gate. All surfaces mount on the same mux, share the auth middleware, and call identical Core methods — so they cannot diverge in behavior. Auth (docs/auth.md): OAuth2 bearer tokens are validated via Hydra introspection (API
source not stored for this graph (policy: none)
nothing calls this directly
no outgoing calls
no test coverage detected