Authorization: Bearer dp_live_…. A token belongs to the organization in which it was created; sending an orgId does not switch workspaces.
Effective permissions
For each request, the API intersects token scopes with the creator’s current permissions, including configured role changes. The creator’s object assignments are applied by the corresponding inventory queries.GET /projects/{id}?include=properties requires both project:read and property:read. Object-scoped tokens cannot create new projects.