- docs/API.md: full REST + WebSocket reference with auth usage
(cookie/Bearer login flow, curl examples), conventions, endpoint
tables, and WS protocol (WS routes are not in the OpenAPI schema)
- server.py: app-level description, openapi_tags grouping, and
tags/responses metadata on all REST routes documenting the error
codes each route raises; hide the SPA catch-all from the schema
- README: link the API reference in the docs index