Buoy Authorization Server
Auth0-backed OAuth 2.0 / OpenID Connect authorization server that issues the bearer tokens the Buoy Symptom Checker API requires. Publishes anonymous RFC 8414 authorization-server metadata and OIDC discovery at /.well-known/, with authorization-code (PKCE S256), client-credentials, device-code, refresh-token and password grants, a JWKS endpoint, dynamic client registration and token revocation. Separate sandbox issuer at auth.sandbox.buoyhealth.com.