Mint a long-lived API key
Create a forge_sk_… key for the calling account. A login token expires in about an hour and, for a Google/Apple account, can only be renewed through an email round-trip — an API key does not expire, so it is the credential for MCP clients, CI, and partner integrations. The raw key is returned in this response and never again: only a SHA-256 hash is stored, so a lost key must be revoked and replaced. Max 20 keys per account (429 over). Requires an existing authenticated session (a JWT, or another API key).
Authorizations
Either a Supabase user access token (from a password login, or the passwordless magic-link flow) or a long-lived forge_sk_… API key. Both are sent as Authorization: Bearer <value> and resolve to the same owner, so every endpoint accepts either. Session tokens expire in ~1h; API keys do not expire and are the credential for MCP clients, CI, and partner integrations.
Body
Human label so the key is identifiable later, e.g. "ci-pipeline". Max 80 chars.

