Inject credentials before publish, read the live token per HTTP request, and surface netx_token_missing instead of a silent 401. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>