Authentication
Dev-auth mode — no sign-in required
This deployment runs with one seeded owner account and no login screen. That is the historical behaviour and the default.
To require a real Google sign-in, set PAXX_AUTH_MODE=google plus the login OAuth client and an allowlist, then restart. The full checklist is in docs/project-brain/AUTH.md; the login screen renders the same checklist live and refuses to let anyone in until it is complete.
Signed in as dh@gopaxx.de (owner), resolved from the seeded owner account rather than a session.