X-API-Key on every V2 endpoint. Keep the key in your backend environment or secret manager.
cURL
provider_id, it must match that provider. Job, field, application, and group operations are limited to resources belonging to your provider.
Active, unexpired keys can use all V2 endpoints; no separate bulk endpoint permission is required. A development key only works with its development environment. Contact support to obtain the appropriate key.
See error handling for 401, 403, 429, and retry behavior.
