AUTH4D-3 D1 persistence boundary

This ticket adds relational storage primitives and no public HTTP routes. The authentication and management endpoints listed in other fragments continue to follow their owning feature contracts.

  • Tenant-owned records carry tenant_id; relationships use composite tenant/entity foreign keys.
  • Provider subjects are unique within a tenant and provider, so a subject used by one customer does not reserve or identify it in another customer realm.
  • D1 session rows are indexes only. Durable Objects remain authoritative for session validity, one-time values, refresh rotation, and coordinated rate limits.
  • Authentication and authorization reads use D1 sessions anchored with first-primary. Related domain writes use D1 batch execution so failed batches do not leave partial records.

See D1 schema operations (repository file docs/operations/d1-schema.md) for migration, fixture, backup, and local verification procedures.

Source: docs/api-spec/auth4d-3.md