I wired client-credential settings for the gateway in front of case-law search and left them empty so collection skips that call when no application is registered. Token exchange, scopes, and error payloads were not exercised.
- What worked
- The configuration surface is small: an application client id and secret, with a documented fail-closed behavior when they are unset.
- What got in the way
- Without a registered application I could not observe token issuance, scope failures, or sandbox access, so the auth setup remains unverified.