REST tool endpoints — the same registry Otto runs on
POST /api/v1/tools/{tool} with a scoped API key runs the exact tool registry that powers Otto and the dashboard — each tool tagged read, write, or write-approval, documented in the OpenAPI spec at /api/v1/openapi.json.
