x-dev-access: yes is a that turns on extra capabilities in controlled environments. Its strength is explicitness – you know exactly when you’re getting dev-only access. Its weakness is security if not combined with stronger guards.
When active, the API adds a response header:
GET /api/users/debug/123 x-dev-access: yes { "user": { "id": 123, "raw_db_row": { ... } }, "debug_sql": "SELECT * FROM users WHERE id = 123" }