report Unauthorized
The 401 path every Portal-authenticated requester routes through: invalidate the credential, then tell the host its session ended.
Kept separate from invalidateCredentials, which stays the plain operation a host-initiated sign-out uses — only a backend rejection is news to the host.
The host is notified even when the invalidation fails: the in-memory token is dropped first, so the session is over either way. The failure still propagates, and every call site already treats this as bookkeeping that must not replace the original failure.