keyward-broker POST /v1/unlock request the broker key share (workload HMAC) POST /v1/lease renew a lease / check revocation (workload HMAC) POST /v1/enroll register a new workload (enroll token) GET /v1/agent.sh on-host agent installer (public) GET /v1/entrypoint.sh container entrypoint shim (public) GET /act// approve or deny from a link (signed link) GET /admin roster, approvals, killswitch (Cloudflare Access)