Authentication

Brain API: send Authorization: Bearer YOUR_API_KEY. Keys look like bj_<12 hex>_<48 hex>, are shown once, and can be revoked or regenerated in the dashboard. Keep them server-side; never put them in browser code.

Livechat: the browser uses your public key (bj_pub_..., safe to expose) to obtain a visitor session token, sent as X-Buejee-Session.

The business is always derived from the key; a business_id in a request body is ignored.