Requires an authorization header instead of x-api-key header. `Authorization: Bearer <access_token>` The rewrite should make it easier to implement this