Address claude-review round 8 on #919: - Security-model docstring: note that opaque cross-client tokens authenticate via the userinfo liveness check (not JWKS/expiry) and bypass the client allowlist, with per-user authz as the gate. - Remove the redundant `if not payload: return None` after the JWT/opaque branches (both already return None on failure) — replace with a comment. - Add test_mcp_path_does_not_use_userinfo_for_opaque_token to pin that the userinfo fallback is management-path-only (MCP path still 401s). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>