Arcana::Auth
Identity / org / API-key model. Postgres-backed (via Arcana::DB).
Stage 1 (this release): models + admin CLI only. Server-side auth enforcement comes in stage 2. Without ARCANA_DATABASE_URL, this module is dormant; current single-tenant localhost behavior is preserved.