- Treat 'undefined'/'null' localStorage values as absent; clear incomplete token/clientId pairs and prompt re-login instead of sending broken headers - Gate authenticated UI on both token and clientId via isAuthenticated - Reject login responses missing access_token or client_id