Exchange a session token for a runtime connect token
Called from the EMBED’S BROWSER with the session token (the token IS the auth, no API key). Admits the session under your per-tenant + the global concurrency caps and your daily session-minutes budget, then returns a short-lived runtime connect token plus the world to play. All cost controls are enforced here. When every concurrency slot is taken the call is placed in a FIFO waitlist and returns 202 with a QueueStatus instead of failing; re-POST the same request every retryAfterMs to poll until you are admitted (200). Daily GPU-seconds are reserved at admission, not while you wait, so a long-queued caller can still get a 402 the moment a slot frees if the tenant’s daily budget ran out in the meantime.
Authorizations
The scoped runtime session JWT from POST /v1/sessions/token. The embed's browser presents it (Authorization: Bearer, or a token body field) to the runtime exchange routes. Not an API key.
Body
The session JWT (or send it as Authorization: Bearer).
Response
A runtime connect token + the world.
The resource id (for a character, the /v1/characters/{id} to talk to).
The SMWorld to play. For a character, world.kind=='character' and world.character carries the render-safe brain (stances/voice/greeting/intro). Never the persona/lore.
Present and true only for TEST-mode session tokens: a fake runtime token, no real Reactor connection. See Testing.

