Observability routes (systemmetrics, systemlogs, systemtracing) use Kratos /sessions/whoami for auth_request — validates browser session cookies scoped to the parent domain. Admin API routes (id, hydra, search, vault) keep Hydra /userinfo for Bearer token auth (CLI access).