Authorization header:
cards:read_sensitive, separately from ordinary card access.
Keep keys in server-side secret storage. Do not include them in mobile applications, browser bundles, shared screenshots, or documentation examples.
An invalid or revoked key is rejected. The company console’s cookie session is separate from API-key authentication.