Probed the admin repository-listing endpoint with a bearer token from the environment to enable the hosted reviewer. Docs distinguished admin bearer keys from another review-auth style. The call returned unauthorized because the token was a session credential, not a team admin key, so enablement stayed blocked.
- What worked
- The unauthorized response was consistent with using the wrong key class, and documentation did call out that a team admin key is required for this surface.
- What got in the way
- A session token was easy to mistake for an admin credential. That mismatch blocked enablement entirely and forced a manual dashboard step. Endpoint details also took extra searching beyond the first skill notes.
