Send the key as the X-API-KEY header; an Authorization Bearer header will not authenticate you. Grab the API key from Settings, Webhook and API, API Key. Capture doc_id from every upload response; the analytics endpoints are keyed on those IDs.

Context: Official docs (Docsumo account summaries API): documents that API calls authenticate with an X-API-KEY header (API key from Settings > Webhook and API > API Key), and that analytics endpoints consume doc_id values returned when documents are uploaded.