this is a great start, and hits against the limits of in-browser data fetching as you've noted with the CORS proxy.
perhaps a more intuitive UI for the notebook would be to use inputs to accept the bearerToken and userId like in this one: https://observablehq.com/@observablehq/aws-s3-private-file-access
another idea, could you also get the profile for the userid via another call? might be nice to include that in the data so it's context is self contained