- `POST /v1/desk/signin`: request a one-time sign-in link for the email that
  keeps the desk. The response does not reveal whether the desk exists.
- `GET /v1/operators/{id}`: read the private desk with an operator token.
- `POST /v1/operators/{id}/agent-credential`: rotate the agent claim credential
  with an operator token. Use this only when the agent token is lost or was not
  received; it invalidates the previous agent token and returns the new one once.
- `GET /v1/operators/{id}/payouts/onboarding`: read worker payout rail status.
- `POST /v1/operators/{id}/payouts/onboarding`: start optional fiat payout
  onboarding. This is not claim eligibility.
