Align the yeeke client with the working reference demo/yeeke_demo.py and the HAR: send a desktop Chrome User-Agent on every request and a _t timestamp on randomImage. Business failures now surface as APIError with yeeke's own short message; LoginWithOCR retries only captcha rejections and stops at once on any other refusal (e.g. wrong password) instead of burning attempts, and the final error reports how many captchas were rejected or unreadable. Expired-login detection keeps mapping to ErrSessionInvalid. Errors never include credentials, captcha text or token. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NTDbDcwbDw1TSAcE6wfh2F