A credential used in another namespace gets 401: a Project API key on
/core/v1 or /api/v1, the Core key on /v1 or /api/v1. How Projects and keys behave is in Projects own assets.
Routing. The reverse proxy sends /v1 and /api/v1 to Core and everything else to Web (proxy setup). Browsers reach /core/v1 only through Web’s console server, which adds the Core key after sign-in and answers 404 for /v1 and /api/v1 (console server). Operator scripts call /core/v1 on Core’s loopback port (script the Core API).
Machine connection API
Nodes, Runtime daemons and the self-hosted installer call/api/v1 with their own credentials. The machine connection API lists every route, caller and credential.