One authorization in progress.
Holds the authorization transaction, which carries client credentials and PKCE
material. Keep it in the host process; never serialize it into a cookie, a
URL, a log line or a durable event. Its inspect/1 output shows only the
credential reference and the redirect URI.
:state is the OAuth state parameter in the authorization URL. A host
that owns its own redirect route uses it to dispatch an incoming callback
to the pending value it belongs to, then calls
Imp.MCP.OAuth.complete/2. A host that lets begin/3 open the loopback
listener does not need it: the listener already matches on it.