Key introspection — the plugin's connection test
No permission required. Any valid key of EITHER class (api or wordpress) may introspect itself — this is the endpoint the Quickstart guide points a brand-new key at.
Authorizations
An API key minted from the dashboard (POST /api/api-keys), of either class: api (prefix pxg_) or wordpress (prefix pxg_wp_). Which class a given route accepts is documented per-endpoint below; presenting a real key of a class the route doesn't accept is 403 WRONG_KEY_CLASS, never folded into 401 INVALID_API_KEY. No cookie fallback exists.
Response
OK
api, wordpress The org's POOLED storage quota (CDN + Processing combined, plan-21 §3/§4) — org-wide, identical for either key class and independent of boundProject.