Browser account and API authorization are separate. The account control above reflects the shared Fracktron browser session cookie. API calls use short-lived JWTs in Authorization: Bearer …; signing into the website does not authorize requests in this console.