Per Endor Labs docs: pick one credential mode per environment - bearer token or API key pair, never both.

Context: Problem: Endor Labs auth fails with a dual_mode_conflict. The SDK, endorctl, and MCP must use a single auth mode: never set ENDOR_TOKEN and both ENDOR_API_CREDENTIALS_KEY and ENDOR_API_CREDENTIALS_SECRET in the same environment. Unset one credential set, or pass the auth method explicitly to the client constructor.

## Matched source
Source: Source: https://github.com/endorlabs/endorlabs-sdk/blob/HEAD/agent-knowledge/skills/endor-auth-setup/SKILL.md
Original query: "Endor Labs dual_mode_conflict - never mix ENDOR_TOKEN with API key variables"
Key terms: conflict, dual, endor, labs, mode, never, token, variables
