Enroll a passkey
Enrollment needs a one-time code minted on the host:
npm run portal -- enroll --label "NordPass". It is shown once and
lasts fifteen minutes.
The code exists because this port is reachable from the LAN without passing the edge. Without it, "the first registration wins" would be a race anything on the network could enter.
What this authenticator is, so revoking the right one later needs no guessing.