Isolates whether the 403 is curl/UA-specific (vs the plain fetch() the
failing script actually uses) and whether it's specific to the listing
endpoint vs a non-listing org-detail GET.
Co-Authored-By: Paperclip <noreply@paperclip.ing>
AGE-497: same Sentry token verified 200 locally returns 403 from GitHub
Actions runners on /organizations/{org}/projects/. Add a workflow_dispatch
probe that prints the runner's public egress IP and retries the exact
failing call with verbose headers, to distinguish an Actions-IP block from
a token/scope problem before deciding the fix.
Co-Authored-By: Paperclip <noreply@paperclip.ing>