- docs/QR-LOGIN.md: canonical QR JSON contract (v/type/relay/svc/code/msg),
reverse flow, client and service rules, security model (server can't
substitute, code is a match+anti-phishing marker not an authenticator)
- SERVICE-GUIDE.md: link the two login modes