(token: string)
| 121 | // token from the CLI device-login); anything else is treated as an API key. |
| 122 | // Same discriminator the MCP plane uses (`mcp/auth.ts`). |
| 123 | const looksLikeJwt = (token: string): boolean => token.split(".").length === 3; |
| 124 | |
| 125 | /** |
| 126 | * Resolve a WorkOS device-login (user_management) access token into a protected |