Smoke script was failing with 401 after the login gate; authenticated requests now match E2E and integration tests.