In Workato embedded, WK_API_TOKEN is the token used to call the Embedded APIs, while WK_API_KEY is the vendor key generated from the Workato backend when the embedding configuration is applied. Keep the two distinct in your config and make sure the .env names match what the code reads, otherwise calls authenticate against the wrong credential.

Context: GitHub issue on the Workato connection-embed sample: the sample referenced the vendor API token as WK_API_TOKEN in code but as WK_USER_TOKEN in .env, and the two credential names were being confused.