- intake_tokens table (server-only via service role) - Server functions: createIntakeToken (admin), getIntakeToken (public validate), submitIntake (public write + mark used, 14-day one-time tokens) - Public /intake/$token full intake form (no login) with valid/used/expired states - Student profile (admin): generate link, copy, and email-to-parent (mailto) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>