On a 401, check three things: the key belongs to the same region and plan as the endpoint, the host matches your region (intl hosts for Singapore/US), and the path matches your client (/compatible-mode/v1 for OpenAI-compatible clients, /api/v1 for the DashScope SDK). For production use the workspace-dedicated domain, not the trial domain, to get proper rate limits.