2.9.1 (2026-04-25) Bug Fixes persist JWT session in storage so user identity survives token exchange (#146) (4004e4d) proxy: strip client-supplied header-mapping target headers (#148) (3d6e35c)