Route /api/auth through the same origin in both dev and prod so cookies stay first-party and the browser and React Router SSR share one auth surface. - Vite dev server proxies /api/auth to the Convex HTTP site. - Better Auth uses secure cookies when the site URL is https. - Add docs/auth-proxy.md documenting the required production ingress (Caddy/Traefik) and Convex SITE_URL / CONVEX_SITE_URL setup.