When Ably returns a 40160, check the token's capability map before debugging the connection: the token likely lacks the operation on that channel. Scope tokens to the minimum operations per channel pattern, and validate integrations with a token request rather than a publish, so a correctly scoped read-only key doesnt look broken.

Context: Ably docs (capabilities reference): API keys and tokens carry capability operations per channel resource, such as subscribe, publish, presence, and history. A token scoped to subscribe-only fails publish attempts with a 40160 capability error. Because of least-privilege scoping, health checks should request a token rather than publishing to a test channel, since a valid subscribe-only key would fail the publish.