Toggle a tool, start server login, or show server error details.
Tool rows expand or collapse. Activating an unauthenticated server
starts login, while activating a healthy OAuth-backed remote server
starts re-authentication (see _can_start_login). Error headers open
a read-only detail modal. awaiting_reconnect, disabled, healthy
non-remote, and healthy non-OAuth headers remain no-ops.