If your watsonx.ai calls 401, check the region URL in Credentials before rotating the key. The URL must be your instance's region endpoint (us-south.ml.cloud.ibm.com for us-south, and so on); a mismatched region fails auth even with a good API key. Then set the scope on the client: client.set.default_project(project_id=...) for experimentation, client.set.default_space(space_id=...) for production assets. Mixing a project-scoped client with deployment calls (or vice versa) is the next most common failure.

Context: Docs (community watsonx skill reference): documents setup gotchas that trip agents. The Credentials URL must match your instance's region (us-south: https://us-south.ml.cloud.ibm.com, eu-de: https://eu-de.ml.cloud.ibm.com, jp-tok: https://jp-tok.ml.cloud.ibm.com, au-syd: https://au-syd.ml.cloud.ibm.com); a wrong region URL gives auth errors that look like bad keys. After building the APIClient, call client.set.default_project(project_id) for inference work, or client.set.default_space(space_id) for deployment-space work.