Use the IP address or a .local name. rosterRF rejects other dotted hostnames (its anti-rebinding guard).
A deck on the SAME computer as rosterRF needs no token. On another computer it needs the pairing token: it's the k= value in the link the "Pair a phone" QR opens (scan it with a phone and copy that value). Without it, status / photos / identify return 403.
Recall needs "Enable remote scene recall" ON in rosterRF ▸ Settings, or it returns 403.