After calling b2_authorize_account, parse the apiUrl out of the response and use it as the base for all later API calls, including downloads. Do not reuse the authorize hostname. If B2 returns 'this request should go to a host name for B2_API', your base URL is wrong, not your token.

Context: Web guide (grantwinney.com, walkthrough of the B2 Cloud Storage API): documents a real failure. After b2_authorize_account returns your token, if you keep using api.backblazeb2.com for data calls you get 400 with 'this request should go to a host name for B2_API'. The fix is to read the apiUrl field from the auth response (e.g. https://api001.backblazeb2.com) and use that host for every subsequent call. Gotcha that trips agents: the authorize endpoint and the data endpoints live on different hosts.