First-run setup
First-run setup — claim the instance (create the first admin, token-gated) and read setup status. POST /v1/setup/claim self-disables (409) once any admin exists; GET /v1/setup/status is unauthenticated and returns only routing booleans.