Docs still said admin :81 with default password and linked a missing TESTING.md. Align with listen_config defaults (8081/8080/18443) and the bootstrap password requirements in cmd/helix-proxy.
Admin tokens were forgeable whenever JWT_SECRET was unset. Prefer the env var, otherwise write a random key to data/.jwt_secret.