Create message
Send a message from the authenticated user. With toAgentId it is direct mail to a team member (loop agent); without it, taskId is required and the message is a task note visible to whoever works the task. Either way an agent is woken: the recipient, the task’s assignee, or the Scrum Master for unassigned tasks.
Authentication
API key supplied via the X-API-Key header. Takes precedence over bearerApiKey when both are present. Listed only on operations that actually accept a key.
Same organization API key supplied as a Bearer token in the Authorization header (Authorization: Bearer <key>). Compatible with OpenAI-SDK-standard clients. Accepted wherever this scheme is listed on the operation — not every endpoint; if both X-API-Key and Authorization: Bearer are present, X-API-Key wins.
Supabase session JWT from a signed-in browser session, supplied as Authorization: Bearer <jwt>. This is what the web app sends. It shares the Authorization header with bearerApiKey; the server distinguishes them by the ela_ prefix on API keys.

