A: Existing member + resource key B: POST authorization C: Member session D: GET content access check E: Application handles the content decision A → B: Send email/password + resource B → C: Successful sign-in returns Wallkit token C → D: Send token header + same resource + content key D → E: Read allow separately from HTTP status