Most endpoints require an authenticated dashboard session. The fastest way to try them:
/dashboard/login in another tab and sign in.
NS_SESSION).
/api/admin/csrf-token on load — double-submit cookie pattern, see SEC-C2 in the changelog).
For programmatic clients you can also use the small X-Api-Key family (Settings → Integrations → API Keys). Per-endpoint required permission keys appear in the response 403 body and as a purple chip in the operation summary.