POST /api/auth/effective-access/batch-can — one decision per item, sharing the base request's scope/company/role fields (batchCanRequestWire embeds canRequestWire).
POST /api/auth/effective-access/can — one decision, self-scoped (the gateway forwards to
authz's /internal/authz/effective-access/can, which rejects any body naming a different
subject than the bearer).
GET /api/auth/effective-access/summary[?companyId=] — the caller's own EffectiveAccessSummary
(apiVersion 1): featureKeys/roleBindings/objectAccess for shell nav/feature gating. kcSub is
gateway-injected from the bearer; there is no way to ask for anyone else's summary through
this client. companyId is optional — omit for the global-scope-only fields.
OptionalcompanyId: string
Typed client over the gateway's self-scoped effective-access surface.