A curated path through the codebase. Each stop explains why to read it at this point and what to take away. Use the arrows, the rail, or your keyboard's ← → keys.
Everything later in the tour assumes this boot order: index.ts decides whether MSW intercepts outbound calls before any app module loads, and server/index.ts decides what happens to a request before React Router ever sees it. A 429, a surprise redirect or a missing header is explained here, not in a route.
MOCKS=true comes from the dev script, not NODE_ENV. The strongest rate limit is chosen with `req.path.includes(...)` against a hard-coded list that omits /forgot-password and /webauthn but still names /resources/login and /resources/verify, which no longer exist, and every limit is multiplied by 10,000 outside production.