QR API

Stateless. Credentials go in the URL, nothing is stored server-side.

GET /qr/<id>/<number>[?t=<epoch>][&width=<128-2048>]   -> image/png
GET /payload/<id>/<number>                            -> text/plain
GET /health                                           -> ok

Fresh signature minted per request (QR1 scheme, t = now).