- added userinfo endpoint
- restructured API paths - added JWT authorization - added login function (without authentication)