When MCP client authenticates with API key, _resolve_token now returns a newly generated JWT. This JWT is stored in the ContextVar and used by all subsequent tool handler API calls - zero extra bcrypt.