External API Credential Separation
The runtime acceptance credential protects diagnostic/operator boundaries. The External API uses a separate Bearer credential.
This probe intentionally submits invalid payload after authentication. The acceptance credential must stop at HTTP 401; the dedicated External API credential must pass authentication and reach HTTP 400 validation.
Evidence appears after the valid intake is accepted.