Trade an api key for a session token of at most fifteen minutes, and send that token as `Authorization: Bearer` on every other call. Call this one with no token.
A refusal is still an answer with a row: token is null and error_code and message say why — an unknown, expired or revoked key among them.
p_on_behalf_of takes a person’s email address and mints a token naming them instead of the key’s own account, so a write records the person who asked for it. What that session may do is what the person, the key’s account and the key’s scopes all allow.
Headers
Preference
params=single-object Body
Trade an api key for a session token of at most fifteen minutes, and send that token as Authorization: Bearer on every other call. Call this one with no token.
A refusal is still an answer with a row: token is null and error_code and message say why — an unknown, expired or revoked key among them.
p_on_behalf_of takes a person's email address and mints a token naming them instead of the key's own account, so a write records the person who asked for it. What that session may do is what the person, the key's account and the key's scopes all allow.
Response
OK

