Auth model
Authenticated endpoints accept:X-Api-Key(recommended for server integrations)- Bearer session token (dashboard / user sessions)
messages:send).
Integrator-focused permissions
Roles (app)
- Member — day-to-day messaging and contacts.
- Admin — member + API keys, invitations, destructive ops.
- Owner — admin + organization-level actions.