Why: provide service-side canonical login/refresh orchestration for session-based web auth.
What: add session contracts, refresh token codec with provider-agnostic secret boundary, grpc session methods, DI wiring, tests, and docs.
Rule: preserve thalos identity ownership and keep transport adapters at service edge.