useAuth() exposes the full verification flow directly - no need to proxy it through your own API routes.
Verify with a code
Verify with a link
For the link a verification email points to (public, no session needed to call it):sendVerificationEmail() is throttled client-side (60s cooldown) - calling it again before that resolves throws, so disable the button while a send is in flight rather than relying only on the throttle to prevent double-clicks.
