What to Check
- Use only the issued API Key for that client.
- Send it using the header or scheme documented for the endpoint.
- Never include the key in a public URL or log.
- Rotate and revoke credentials when exposure is suspected.
- Treat 401 and 403 as different authentication or authorization failures.
Current Jitra Workflow
The API Keys page creates credentials; it does not show or change the authentication contract for individual endpoints.
