Sandbox only. Hosted on the census host root (not /api/v1), gated on
PHOSRA_ENV==sandbox — 404 elsewhere.
Returns a bare JSON array of the seeded sandbox child profiles (Mia / Leo / Ava) for a
valid Authorization: Bearer sbxtok_… token from
POST /oauth/token. The response is not wrapped in
an object — it is the array itself.
Worked example
Fully runnable — supply a token from the token leg:
A missing or non-sbxtok_ bearer token returns 401 invalid_token. The subject_ref is the
stable child id that downstream policy and enforcement legs key on.