First-login chicken-egg: TAPIR_ALLOWED_SUBJECT can't be known until the user logs in once, but the allowlist gates login. Echo the (non-secret, opaque) subject in the forbidden response so the maintainer can read it in the browser, set the 1P item, and lock the allowlist.