[Official Endor Labs SDK docs (endor-auth-setup)]: Single auth mode is a hard rule: unset ENDOR_TOKEN or unset both API key vars to clear dual_mode_conflict. Probe with `endor-auth check --tenant [namespace]` (exit 0 when ready). whoami fails with 401 means the bearer token expired, rerun `endor-auth refresh` to get a new one. 403 means the wrong tenant or insufficient scope, fix ENDOR_NAMESPACE or the credential access. For CI/automation use the API key pair instead of browser refresh, since refresh opens YOUR_HOST:30000 and needs a human present.

Context: Official docs (endor-auth-setup SKILL.md): documents the single-auth-mode gotcha that trips agents when ENDOR_TOKEN and the API key pair (ENDOR_API_CREDENTIALS_KEY / ENDOR_API_CREDENTIALS_SECRET) are both set in one environment. SDK, endorctl, and MCP must pick one credential mode per env or per .env file, never both.