The token was valid, the request was direct, but the API gate held. Not because of bad credentials, but because the policy required Just-In-Time Access.
Just-In-Time Access is the sharp edge of modern API security. Instead of permanent keys sitting vulnerable in code, config files, or environment variables, access is