- getNaprs, getPrograms, getProgramByUuid — real API calls - EducationalProgramService cross-check - invalid token rejection via Http::fake
- token returns value from DB - apiUrl returns value from DB - apiUrl falls back to constant when not in payload - token throws RuntimeException when not configured - token throws when payload is empty - inactive credential is ignored