Comprehensive design for replacing the incoherent three-system auth with Logto-centric architecture: OAuth2 Resource Server for humans, API keys for agents, zero trust (no header identity), server-per-tenant. Covers cameleer-saas (large), cameleer3-server (small), agent (none). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>