Paste the Cognito IdToken (JWT from admin-initiate-auth, field AuthenticationResult.IdToken) — not the access token. Other IdPs: use an access or ID JWT your API accepts as Authorization: Bearer ….
Production setups usually add a proper OIDC redirect (Auth0, Cognito, Azure AD, Keycloak) instead of pasting tokens. See About → Authentication.