Authenticate with POST /v1/auth, then call the remaining routes with a Bearer token. Usage, topup packs, plan changes, and topup jobs are in the spec below. The Webhooks section describes the signed POSTs we send to your URL — they are not routes you call.