Cookie-aware whoami
Minimal whoami endpoint. Returns { user } when the mnemom_session cookie is valid; returns 401 otherwise. Preferred over GET /auth/me for cookie-only browser sessions — /auth/me is bearer-only and preserves its legacy response shape unchanged.
Authorizations
HttpOnly, Secure, SameSite=Lax cookie issued by /v1/auth/sign-in (or the SSO / email-callback flows). The value is an AES-256-GCM-encrypted blob of {access_token, refresh_token, issued_at, auth_method}. Browser clients include this automatically with credentials: "include".
Response
Authenticated session.
Supabase user shape. Fields beyond id and email are passthrough.