API Key
Authenticate every request with the x-api-key header
The API Key (also called App-Key) is the simplest way to authenticate. It is a
static key that you send in the x-api-key header of every request.
API Keys are issued by Voices. Request yours from the Chat Bridge team: it comes preconfigured with the account and the channel it is enabled for, so you never send them on each request. One API Key enables one channel; request one per channel you need. The Tools endpoints accept any API Key.
Usage
Keep the key on your servers only. Anyone holding it can send traffic on behalf of your account; if it is exposed, ask the Chat Bridge team to disable it and issue a new one.
API Key or OAuth 2.0
Both methods identify the same App-Key, so account, channel, webhooks and rate limit are identical whichever you use, and both sets of credentials are provided by Voices.
If a request carries both headers, Authorization: Bearer takes precedence.
An App-Key can be switched to OAuth 2.0 only; from then on x-api-key is
rejected with 401 and errorCode 450.

