Create a key at API keys, then send it as Authorization: Bearer <key>. API keys provide read-only access.