Adds /vendor/auth-policy route with MFA mode (off/optional/required) and passkey (enabled/disabled, optional/preferred/required mode) controls, including a confirmation guard before enforcing required MFA. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>