The API uses the BearerAuth security scheme (HTTP Bearer, JWT).
BearerAuth
Get a token from /auth/login or /auth/employee/login, then send:
/auth/login
/auth/employee/login
When authenticated as a subuser, include a target customer header for customer-scoped endpoints: