insecur web BFF

The browser talks only to this Worker. API bearer tokens stay server-side on the private Service Binding hop to insecur-api.

Open /whoami with a valid WorkOS session cookie to exercise the BFF to API path end to end.