Begin enrollment: mint a secret (encrypted at rest) and return it + the otpauth:// URI.
Re-running before enable simply rotates the unverified secret; 409 once 2FA is live (disable
first — prevents silently swapping the authenticator without a code).