applyToken
Applies the fresh credential to the request that will be retried.
Called only when refresh returned true.
The implementation should mirror whatever KAuthProvider does — inject a Bearer header, an ApiKey header, or leave the request untouched if the auth scheme is cookie-based (Ktor picks up the updated storage automatically).
Parameters
request
The original failed request, ready to be mutated before retry.