Omitting scopes uses the default tenant API-key permission set. Supplying scopes creates a custom permission set. Additional opt-in scopes are advertised by GET /api/v1/api_key_permissions.
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.