Identities for entities did.bot
agent llm did

feat(oauth): relay sign-in decisions and approve by token master

The daemon follows the accounts it issued, long-polling the server for authorization requests naming them, and carries whatever is waiting for a context back on that context's next report. `didbot pending`, `didbot approve` and `didbot decline` are the agent's side of it. An approval names a token and never an account: the daemon finds the record it is holding that token in and signs in as the account that record names, so there is no DID for a caller to fill in with somebody else's. `didbot confirm` still works, resolving its URL to a held record when there is one. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Change-Id: Ibd98c02be0cd17d5ba529efba085dfcd0e03a0bb