Public catalog reads allow anonymous access with a lower quota. If you send Authorization, the credential must be valid and include the endpoint scope (anime.read for catalog, search.read for search). Invalid keys never fall back to anonymous access.
The API accepts Authorization: Bearer <API_KEY> and Aniyori Identity OAuth access tokens. Use keys on the server, never in a public browser bundle or URL.
An API key identifies an application. A user token identifies a user and delegated permissions. Keys can never manage applications or access /v1/me.