GET /health → { ok: true }
GET /index.json → { items: [...] } (no file contents)
GET /r/button.json → free item (public, includes files[].content)
GET /r/pro/paywall-sheet.json → Pro (Authorization: Bearer KEY)
GET /schema.json → lumioui.json JSON schema Pro auth: 401 missing/invalid, 402 expired/canceled, 404 unknown name. Names are validated ([a-z0-9-]) against path traversal.
Build payloads with pnpm build:registry — source of truth is packages/ui|pro|screens plus sibling meta.json.