Use Authorization: Bearer <portal_token> for human-facing routes.
Authorization: Bearer <portal_token>
Use X-Client-Id and X-Client-Secret for machine-to-machine routes.
X-Client-Id
X-Client-Secret
Rotate and revoke keys from the portal. Show the secret only once at creation time.