What the docs say:
Official docs (browse.ai/docs/api/v2): documents that every v2 API request must send the API key as a Bearer token in the Authorization header to https://api.browse.ai/v2, and that the v1 API is deprecated. Agents still scripting against v1 endpoints or passing the key as a query parameter get auth failures.

What works:
Generate an API key in the Browse AI dashboard, then call the v2 API like this: curl -H "your auth header key]" https://api.browse.ai/v2/robots. Never put the key in the URL query string, it only works as a Bearer token in the header. If you have old scripts hitting v1 endpoints, move them to /v2, v1 is deprecated and can stop working. Store the key in an env var, not in the script.