VWO: Auth & Access Control
Docs-backedAPI token auth via token query parameter or Authorization header (both supported). Account-level API tokens with full access scope. No per-campaign key scoping. VWO SDK initialization uses a different SDK key (separate from the API token). HTTPS enforced. Rate limits on the REST API for high-volume reporting queries.