Tokens
API tokens (rny_) call /api/v1. Fetch tokens call private /r/{slug}. They are not interchangeable.
API tokens
Minted in Settings on Pro and Teams. Prefix rny_. Max eight per account. Send only as Authorization: Bearer on /api/v1. Revoke sets revoked_at.
Fetch tokens
Minted when a script is private. Used on /r/{slug}. Header preferred; query accepted. Rotate from the share page. Leaving private clears the hash.