Authorization header:
- Create keys in the console: playground.aircaps.com → API keys. A key is shown once; AirCaps stores only a hash.
- One key, both models. The same key works for the REST API and the streaming WebSocket.
- Up to 10 active keys per account. Use one per service or environment so you can revoke them independently.
- Revoke a key in the console. It stops working within 60 seconds.
- Keep keys server-side. Never put a key in a browser, mobile app or public repository.
401 unauthorized. A disabled account returns 403 account_disabled.
Account settings (keys, webhook signing secret, profile) can only be changed from the console, not with an API key.