v2.1.0 — contract honesty

- sessions response schema reconciled to the reference server (drop phantom mfa_level/friendly_name/approx_location; add acr/amr[]/user_agent/ip_first_seen)
- GET /healthz added to the contract
- canonical amr registry (pwd/webauthn/otp/phone_otp/recovery + provider-id)
- security-model + sessions docs corrected to the implemented reality (removed unbuilt Vault key custody, revocation broadcast, Ed25519 device binding, jti replay, Merkle audit)
- acr aal2 definition fixed: passkey login is aal1
- reference schema marked non-authoritative + drift named