The users and projects_users_search groups don't exist; the routes collect as other:users and projects:users_search, so PermissionsAreValid rejected any real token and the tool was unreachable. Also strip emails on the project-scoped search path.