atproto git client

docs: reject the confidential OAuth client, with the reason master

A confidential client must be a web client, and only native clients may register a loopback redirect, so it would need a hosted HTTPS callback between a login and the PDS. atgc will not take a runtime dependency on a server to log in. Recorded as a rejection rather than deleted so it is not proposed again, and architecture.md no longer offers it as the way out. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>


+56 -9
2 changed files