# Zapier authentication ## Target (after PR 5) - Type: custom / API key. - Fields: `apiKey`, `baseUrl` (default public zappier origin). - Header: `x-api-key`. - Test: `GET /v1/status` or `GET /v1/me` if added. - Errors: 401 invalid key; 403/402 quota or unpriced endpoint → user-visible upgrade text pointing at `/portal`. ## Today (imported CLI app) - Bearer middleware API key `zmw_…`. - Test: `GET /zapier/v1/auth/me`. - `afterResponse` maps 402 and `PLAN_UPGRADE_REQUIRED`. Do not send Verae JWTs to Zapier. Middleware (or zappier→middleware) logs into Verae server-side.