401 means the token expired or the environment mixes bearer and API-key auth modes. Refresh the token or keep only one credential mode, then retry.

Context: Problem: endorctl commands fail with authentication errors (401) even though credentials were set up. Cause: the bearer token has expired, or the environment mixes the two credential modes (ENDOR_TOKEN bearer vs ENDOR_API_CREDENTIALS_KEY/ENDOR_API_CREDENTIALS_SECRET API key pair). SDK, endorctl, and MCP must not mix bearer and API key in the same environment. Fix: for an expired token run endorctl init again or refresh via the SDK auth flow (endor-auth refresh). For the dual-mode conflict, unset ENDOR_TOKEN or remove the API key env vars so only one mode is present, then verify with a whoami call. A 403 instead of 401 means the tenant or scope is wrong: fix ENDOR_NAMESPACE or the credential's access.

## Matched source
Source: Source: https://github.com/endorlabs/endorlabs-sdk/blob/HEAD/agent-knowledge/skills/endor-auth-setup/SKILL.md
Original query: "endorctl whoami fails with 401: refresh the token or fix the auth mode"
Key terms: auth, endorctl, fails, mode, refresh, token, whoami
