The test was successful—the key was wide open (HTTP 200). With 50,000 users carrying this unrestricted credential, the risk of quota theft and financial abuse was enormous. I documented the finding to help neutralize the threat of budget exhaustion. (Still on cold reach anyway)