cli: route `entire activity` to entire-api when configured
Commit

Assemble the entire-api client for the current repo and point activity
at it. The command already calls /me/activity and /me/commits — the exact
paths entire-api serves — so this is a routing change, not a response
rewrite:
- auth.ResolveEntireAPIToken mints a jurisdictional identity token for an explicit audience (no /.well-known; entire-api serves none), exchanged from the active login context.
- newEntireAPIClientForCurrentRepo ties it together: resolve the repo's mirror → cell/jurisdiction, fill the base-URL/audience templates, mint the token, return a client pointed at https://{cell}.api.entire.io.
- runAuthenticatedActivityAPI prefers that client and falls back to the data API when the ENTIRE_API_* templates are unset or the repo isn't routable, so existing users are unaffected.
Fallback is silent; genuine failures (control plane down, token rejected, bad template) surface. recap moves next.
Co-Authored-By: Claude Opus 4.8 noreply@anthropic.com Entire-Checkpoint: 690550a49bd7
Checkpoints
Checkpoint 1