Executive summary
The protected remote Evaluation Observatory was diagnosed and corrected so an authorized viewer needs only their Cloudflare identity, not a separately carried Hiro API key.
The browser-side API-key prompt was obsolete for the read-only dashboard and was removed.
The Observatory listener now preserves the tunnel's immediate loopback peer for its narrow reverse-proxy authorization path; non-loopback and tailnet behavior remains governed by the existing configuration.
Local API and dashboard checks passed, and the protected remote page loaded successfully with no API-key control.