meigen_sk_ followed by 32 characters. The full value is shown only at creation — copy it immediately.
Pass the token as a Bearer credential on any authenticated endpoint:
Token management itself (
POST / GET / DELETE /api/tokens) is authenticated with a logged-in browser session, not with an API key — an API key cannot create or revoke tokens. Manage them from account settings.