Decision session

RSI snapshot for a token and timeframe via /api/session.

Watchlist mutations (optional)

Session load uses open GET /api/session. To add or remove watchlist entries from the browser, paste the same APP_ACCESS_TOKEN value configured on the server (stored only in sessionStorage on this device — never embedded in the app).