Access model
- - Existing public site APIs stay unchanged for the frontend.
- - Developer REST endpoints require
Authorization: Bearer. - - Raw keys are shown once; only hashes are stored.
- - Usage is tracked by key, quota tier, daily window, and revocation state.