- /funcs/<namespace>: user opens URL in browser, no auth needed service uses SLESS_SERVICE_TOKEN to query operator internally - /funcs?token=<jwt>: token as query param (bookmarkable URL) - /funcs: returns usage hint with both URL formats - SLESS_SERVICE_TOKEN set via kubectl set env (not stored in repo)