API Keys (Server-to-Server) Scoped to a Project. Can override Context Size per key. Always send as Authorization: Bearer <API_KEY>. Never embed in clients.