63c58b5bb3
Single-user personal app threat model is theft-of-device, not stolen-cookie. 30-day idle re-prompts created friction without proportional security benefit. Server TTL and client max-age remain in sync via shared constant. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>