Covers the issue test plan: form renders and posts to the endpoint; token is read from config, never hardcoded in source; a failed-token response shows a user-safe error without leaking the secret; confirmation on success.