[AUTHENTICATION]
No API key or authentication is required. All endpoints are public, read-only or stateless-compute, and rate limits are enforced at the platform (Vercel) level. Every response — success or error — is JSON with a Content-Type: application/json header.