Authorization: Bearer <key>. Keys are issued per organization, scoped to a specific environment (live or test), and carry the minimum permissions needed for your integration.
There is no token exchange step. Include the API key directly on every request.
Common scopes include:
entities:readandentities:writefor entity managementconnections:readfor institutions and connection readsconnections:writefor connection onboarding, credential updates, sync, and deletionaccounts:readfor account datatransactions:readfor historical browse and syncwebhooks:readandwebhooks:writefor webhook registration management