The session token: send it as Authorization: Bearer <sessionToken> on
the physician-side routes. Browser-safe — it names one physician, expires,
and can do nothing your key could not have let that physician do.
When the token expires; re-mint before then (2 minutes early is plenty).
The base URL of THIS API (through /v1, no trailing slash) as seen from
the request — returned per mint, like the embed mints return their
transport, so a browser bundle never bakes in a host that may move.
The physician the session was minted for.
POST /v1/physicians/{id}/sessionresponse — a physician session token and everything a browser client needs to use it. Hand the whole object toconnectPhysicianfrom@natzar/client/physicianand it is self-configuring.