- Remove the authless "sole connected phone" fallback and SB_REQUIRE_MCP_AUTH:
an unauthenticated request no longer reaches whichever phone is online alone.
- Mcp-Session-Id is no longer a credential; the Bearer token is checked on
every request (MCP auth spec).
- Refresh tokens live 90 days (was 30, equal to the access token, so they
were always dead when first needed).
- A rejected refresh no longer counts toward the IP ban: a client with an
expired token was retrying into a self-renewing ban on its own IP.
- 401s carry the RFC 9728 WWW-Authenticate discovery header.
- claude.ai connector section now documents the OAuth login flow as the
primary path, with the authless single-user fallback as Option C.
- Project structure, requirements, and .env docs updated for the OAuth +
governor modules; pointer to .env.example for the governor knobs.
- Tools table covers the extended output types, the escalate hold
contract, and feature_index for multi-motor devices.
- Safety Features section documents the governor.
- CHANGELOG.md records v1.1 and the v1.0 baseline.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>