Context: Official docs (OTLP endpoints): documents that every OTLP ingestion request must include the API-Token header with the API token of a valid service account that has write permissions. Only OTLP v1.0 and higher are supported, all requests must be encrypted with TLS, and compression options are gzip, snappy, or zstd (zstd recommended). Compressed payloads should stay under 16 MB and metric payloads 

Set up ingestion with these requirements checked off. Create a restricted write-only service account in Chronosphere and use its token in the API-Token header of your exporter config. Make sure your endpoint is https, not http. Compress with zstd. Keep compressed batches under 16 MB and metric payloads under 10,000 items; if you blow past the item count, split into multiple requests. Example OTLP HTTP metrics endpoint: https://TENANT/data/opentelemetry/v1/metrics, gRPC at TENANT:443. If ingestion returns 401, recheck the token's service account permissions before anything else.