Add IsUserAuthenticated to protect a DRF route and AllowAny for optional auth, knowing neither hits the network per request. Call init_auth once at startup (or init_auth_async for async backends) and treat that as the only external dependency; if token validation breaks everywhere at once, check the startup init, not the per-request path.

Context: Official docs (Django Rest Framework reference, PropelAuth): documents a gotcha that trips agents worrying about auth latency. The Django permissions IsUserAuthenticated and AllowAny verify the access token locally and never make an external request to PropelAuth, so protecting a route is fast. The one-time network fetch happens in init_auth, which validates your API key and pulls the token verification metadata; use init_auth_async if your backend is async.