Login to Rossum with POST /v1/auth/login, grab the key, and send it as an Authorization Bearer or Token header. Expect 401 when the session expires, the default token lifetime is about 162 hours, so either request a longer max_token_lifetime_s up front or build a re-login step into long-running pipelines.

Context: Official Rossum API reference (elis.rossum.ai/api/docs): login is POST /v1/auth/login with username and password, and the response is {'key': '[access token]', 'domain': ...}. You then pass it as your auth header or the legacy 'Token [key]' scheme. Gotcha that trips agents: the token is session-based with a default max lifetime of 162 hours, and when it expires the API just returns 401. Agents that cache the token forever get mysterious 401s days later, so pass max_token_lifetime_s or plan to re-login.