Evidence-backed facts
- GitLab documents some public endpoints that need no authentication, while most API requests require a supported credential. informative
- A token type or successful login does not authorize every mutation; project, group, user, role, and endpoint rules still apply. informative
- Supported API credentials include OAuth, personal, project, group, and endpoint-limited CI job tokens, normally carried in authorization headers. informative
- Deploy tokens cannot call the public REST API, job tokens cover only documented endpoints, and administrator impersonation must never be a default connector mode. informative