When creating a fal key for an agent that only calls models, pick the API scope and nothing more. If your app needs private models or the fal CLI, generate a separate ADMIN-scoped key and keep it out of the inference path. Send the key on every request as an Authorization header with the Key scheme, literally the word Key followed by the key value, not Bearer, or every call 401s no matter how valid the key is.

Context: Official docs (key-based authentication): documents the two key scopes that trip agents up. Keys are scoped, and there are only two scopes: API and ADMIN. The API scope covers ready-to-use models and API-scoped platform endpoints, which is all a model-consuming app needs. The ADMIN scope is required for private models and CLI operations. Generating an ADMIN key for a simple inference app, or an API key and then wondering why private-model calls fail, are both common missteps.