v1: JWT-only, no API key required. v2: requires an API key (X-API-KEY) and, for protected routes, a JWT Bearer token.
To use v2: 1) Log in as dev, 2) Generate an API key, 3) Store it safely, 4) Send it with every X-API-KEY header on /api/v2 calls.