Operator Surface
Admin API routes are isolated under `/api/v1/admin/*`; user DApp routes stay under `/api/v1/*`.
NFT eligibility 列表需要管理员会话。