[Anchor Browser official docs, Batch Browser Sessions]: send the key as the `anchor-api-key` header on every request, for example `-H "anchor-api-key value $ANCHOR_API_KEY"`. Requests with `Authorization: Bearer` fail auth. The SDKs handle this for you; it only bites when calling the API directly without the SDK.

Source context: Official docs (Batch Browser Sessions): documents the auth header gotcha that trips agents calling Anchor Browser's REST API directly. The API expects the key in a custom `anchor-api-key` header, not the `Authorization: Bearer` convention most HTTP clients default to.