secrets.compare_digest raises TypeError instead of returning False when a str argument contains non-ASCII characters, turning a bad admin token into an unhandled 500 instead of the expected 403. Encode both sides before comparing. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>