Header
Authorization may send x-arena-key: arena_sk_… instead. HTTPS only.
Scopes
GET /me and GET /usage accept any valid key. GET /status needs none.
Sessions
Key management uses a person’s session instead of a key: the website’s cookie, or a signed-in CLI’s session token as the bearer. There is no guest or anonymous access.The playground in the API reference sends requests through Mintlify’s proxy. Use a key you can revoke, with only the scopes you need.