Health
API key (list products)
ReplaceBASE and use a real key in production.
OAuth2 token then Bearer
Recommendations
The recommender uses the same HoJ bearer token. Passbrand and locale; the BFF resolves the upstream channel_id.
RFC 7807 errors
Failed calls returnapplication/problem+json with type, title, status, detail. Use -v or log response bodies when debugging 401, 403, 429, 502.