secure keys off NODE_ENV so the auth_token cookie is HTTPS-only in prod while still working over plain HTTP on localhost in dev. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>