Make real remote web API requests under explicit permission and environment constraints. Use before live HTTP, SDK, CLI, GraphQL, RPC, or integration-test calls, including unauthenticated reads.