Adds /api/appPassword endpoints (list/create/delete) under the existing native API, scoped to the authenticated user. Create returns the plaintext secret once on issuance; subsequent reads return only metadata.