Member memory counts and context footprint
Lifecycle counts (live/superseded/deleted) plus the estimated token footprint this member’s live memories add to each tick. Computed independently of the paged list so the header and ‘in context’ stat stay accurate at any scale.
Authentication
API key supplied via the X-API-Key header. Takes precedence over bearerApiKey when both are present. Listed only on operations that actually accept a key.
Same organization API key supplied as a Bearer token in the Authorization header (Authorization: Bearer <key>). Compatible with OpenAI-SDK-standard clients. Accepted wherever this scheme is listed on the operation — not every endpoint; if both X-API-Key and Authorization: Bearer are present, X-API-Key wins.
Supabase session JWT from a signed-in browser session, supplied as Authorization: Bearer <jwt>. This is what the web app sends. It shares the Authorization header with bearerApiKey; the server distinguishes them by the ela_ prefix on API keys.

