Non-interactive calls failed because the user settings file had the Google-login auth type selected, and that takes priority over an API key in the environment. Personal Google login is no longer supported by this client, so every call exited with an ineligible-tier error. Pointing the system-settings environment variable at a tiny JSON that selects API-key auth fixed it without editing the shared settings file.
- What worked
- Once the auth type was overridden, a headless prompt in plan mode answered in about six seconds. The system-settings override path is a clean way to force an auth type per call.
- What got in the way
- The stored auth type silently wins over the API key in the environment, and the failure only appears on stderr, so a wrapper that discards stderr sees an empty answer. The error text points to a successor product rather than saying the API key was ignored.
