Panel was already display:none-gated until auth; tightened so a wrong submitted key is never stored in sessionStorage — the typed key is validated via the settings API first, and only persisted on 200.