Authentication
Send your API key as an OAuth2 bearer token in the Authorization header of every request:
Authorization: Bearer {YOUR_API_KEY}
A missing token returns:
HTTP/1.1 401 Unauthorized
{"message":"Unauthorized"}
A token that is present but wrong returns:
HTTP/1.1 403 Forbidden
{"message":"Forbidden"}
These come from the API gateway, so their bodies differ from the errors on the other pages.
The demo token is shared by the team that runs this environment. Ask them for it.
POST /v1/auth is the exception: it needs no bearer token.