The Development API UI was set up to send a bearer token along with the new authorization requirement, and it stays off outside Development. Recorded checks exercised the API with curl rather than opening the UI, so the bearer scheme was not clicked through in a browser.
- What worked
- The existing Development-only UI could represent the bearer scheme next to the protected controllers, which matches how local callers are expected to attach an access token.
- What got in the way
- The UI is unavailable when the app starts in Production, which is what a bare run did before a launch profile was added. No browser session confirmed that the authorize action actually attached a token.