- POST/PATCH/DELETE /api/my-events (organizer only) - GET /api/my-events (mine) - GET /api/events/u/{id} public by id; private accessible via ?token= - Validation; ownership checks