The 401 was the session wall, not a missing token. The ingest route now uses the shared Bearer secret, and both apps default that secret so Coolify vars are optional.
Co-authored-by: Cursor <cursoragent@cursor.com>
A URL in BACKUP_INGEST_TOKEN was treated as a missing token. Errors now say to put the URL on AIGen and the same secret on both apps.
Co-authored-by: Cursor <cursoragent@cursor.com>