GET /api/platform/catalog — the full module catalog (routing metadata; no auth gate at registry's own layer, but the gateway still requires a bearer per mountPlatformRoutes).
POST /api/platform/admin/modules/{key}/disable — same guard as enableModule.
POST /api/platform/admin/modules/{key}/enable — requires the caller to hold
auth.platform_administration.access (superadmin); 403 KibanApiError otherwise.
POST /api/platform/admin/platform-roles — grant role (only "kiban-superadmin" exists) to
the user identified by subjectId (their Keycloak subject id). Same guard as enableModule;
404 when identity has never seen the subject; 422 for any other role.
DELETE /api/platform/admin/platform-roles/{role}/{subjectId} — revoke it. 404 when the subject does not hold the role; 409 CONFLICT when it is the platform's last superadmin (the caller revoking themselves included).
Typed client over the gateway's
/api/platform/*capability/catalog reads and superadmin-guarded module enable/disable mutations.