OK ID auth placeholder. Later this route will redirect to the official OAuth/SDK authorize endpoint. Put client_id/app_id and redirect_uri in .env; keep client_secret backend-only.