Authorization header as Bearer YOUR_KEY. Keep the key in your
integration’s secret store. Never place it in a URL or a public documentation file.
Scopes
Scopes limit the key. They do not replace campaign membership, ownership or
role checks. A key cannot grant you access your account does not have.
Verify a key
CallGET https://www.lorvia.online/api/account/api-keys/whoami with the bearer
header. A successful response contains accountId, keyId and scopes.
Campaign endpoints can return 404 for missing or unauthorized resources.
On 429, wait for the Retry-After interval before retrying.