One endpoint authenticates with a bcrypt-hashed key, runs a 7-check security scan on your HTML, then stores it in private R2 — returning a permanent shareable URL.
Bearer . Key must be ≥ 12 chars — 401 fires immediately with no DB hit.revoked_at IS NULL. Shields bcrypt from brute force.