The API plugin's enabled/route/session_enabled/cors/rate_limit config lived only in the untracked user/plugins/api/api.yaml, so a fresh install (prod) had no working /api — Admin2, which authenticates via /api/v1, could not log in. Move the functional config into the tracked override user/config/plugins/api.yaml (merged over the plugin defaults). Secrets (JWT) stay in the gitignored api-private.php; the auto-generated popularity salt is intentionally not committed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Np4cMQLF77i664CAQXySzU