Send
Authorization: Bearer <token> for authenticated operations. Public application URLs and public model discovery are exceptions; never assume a newly exposed sandbox or container URL is protected by workspace authentication. See authentication and each workload’s authorization option.
Check the operation’s response fields as well as HTTP status. Some gateway operations report ok: false inside a successful HTTP response. The workspace API guide explains the distinction.