Portal session

Sign in with an API key

Machine clients keep using X-API-Key or Authorization: Bearer. This form stores the same key in an HttpOnly cookie for the HTMX portal. OpenID Connect / Keycloak is a later phase.