Internal reference

API Documentation

Admin endpoints require an Authorization: Bearer <token> header. Listing/export uses ADMIN_TOKEN; deleting and flushing require the separate ADMIN_DELETE_TOKEN. Keep both tokens secret.