Authentication
Google Sign-In
Exchange a Google OAuth2 access token for a BlobHub token pair.
The access token is the entire request. Who it belongs to is established server-side against Google — the
token’s audience is checked to confirm it was issued to BlobHub, and the account it signs in is read from
Google’s profile response. Nothing about the identity is taken from the request body.

