--- id: TASK-001 title: dots auth accepts widget tokens as valid status: "\U0001F7E6 Backlog" assignee: [] created_date: '2026-07-30 01:23' labels: - bug dependencies: [] priority: medium ordinal: 1000 --- ## Description auth verifies via GET /api/widget/data, which accepts both widget and CLI tokens — pasting a widget token 'links' successfully, then every write 401s. Verify against a CLI-only endpoint or document.