Account-wide, so it is meant for a trusted environment — a server, a build step, an internal
tool. Anyone who reads the token can spend the account's credits, so do not ship one in a page
you serve to users; use ClientKeyAuth there. The SDK sends it as
Authorization: Bearer <token>~<connectionId>, appending a per-connection id the D-ID
authorizer strips before it validates the token.
A bearer token for the Agents API.
Account-wide, so it is meant for a trusted environment — a server, a build step, an internal tool. Anyone who reads the token can spend the account's credits, so do not ship one in a page you serve to users; use ClientKeyAuth there. The SDK sends it as
Authorization: Bearer <token>~<connectionId>, appending a per-connection id the D-ID authorizer strips before it validates the token.