The v1 contract uses Authorization: Bearer <YOUR_API_KEY>. Keys belong in your server environment, not a query parameter, browser bundle, analytics event or screenshot. Read and write scopes are separate. Keys are shown once, support expiry and can be revoked immediately.
All documentation