/api/v1/api-keys/grantable-scopesGETak_ prefix), sent as a Bearer token or an ?api_key= query parameter. Each endpoint requires the read scope for its resource (e.g. org:rates:read for rates). Token in: headerAuthorization header, an invalid token, or a token lacking the required scope. This is free text whose wording can change, so branch on status (or the HTTP status code) instead of on this string.message. One of bad_request, unauthorized, forbidden, not_found, conflict, service_unavailable, upstream_error, service_error, or internal_error.rate_limited. Branch on this to detect a throttled request.rpm for the per-minute cap or daily for the daily one.