Token is kept in localStorage and sent as a Bearer header.
localStorage
Toggle inventory off → check returns 402; on → 200.
inventory