pub fn generate_token() -> Result<String>
Mint a fresh random auth token: 16 CSPRNG bytes rendered as 32 hex characters. Loopback bind + this token are the only security boundary, so the token must be unpredictable.