Persistence as shared infrastructure: the machine’s registry, written and
read by lf directly — lfd is one more client, not the owner. This
module owns the sqlite registry, schema migrations, and registry API
(Store and its per-domain traits).
Provider auth flows: device-code/browser OAuth for the agent and PM
providers, token extraction from vendor CLI artifacts, and store-direct
persistence into lfdb provider tokens.