Authorization header:
POST /api/tokens from a signed-in dashboard session. Keys are the same ones used by the MCP server, the SDKs, and the CLI. See Authentication for the full picture across interfaces.
Two security schemes
The spec declares two bearer schemes. Each endpoint’s reference page shows which one it expects.
Only the access key scheme is meant for integrations. The session scheme exists because the Xpoz dashboard calls the same API, and those endpoints appear in the reference so the spec is complete.

