API tokens are minted in your instance's admin Developer Portal. Each token carries its own scopes (ask, read, write, tools) and can be bound to a person so it inherits that person's permissions. The API is off until a token exists.
Off by default matters: before the first token is created, the external API answers 503, not an open door. From the Developer Portal you can mint, rotate, and revoke tokens, each with the narrowest scopes the job needs.
No instance yet? The waitlist at falkster.ai/waitlist is the way in; every instance ships with the Developer Portal.