Demo OAuth 2.1 Authorization Server Endpoints: GET /.well-known/oauth-authorization-server GET /.well-known/jwks.json GET /authorize (PKCE required; append ?user=alice|bob for headless) POST /token