You understand how keys, tokens, and permissions protect APIs and how frontend apps should react when auth fails.