Covers self-service password reset via Logto Experience API, TOTP + backup code MFA with per-tenant enforcement via JWT claims, and a server handoff document for cameleer-server MFA enrollment. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>