When you enumerate channels or read channel status with Ably, grant the channel-metadata capability on the token; publish and subscribe dont cover it. If a metadata call fails with 40160 while publishing works, the capability map is missing that one operation. Design tokens around the operations list, not just the channel.

Context: Ably specification tests (uts/rest/integration/auth.md): a channel status request requires the channel-metadata capability, not publish. A token with publish on a channel is still refused when it asks for channel metadata. Capabilities are per-operation, and metadata is its own operation alongside subscribe, publish, presence, and history.