API-Token based

authorization: Bearer <api_token>

Allowed for the following routes:
- users/onboarding
- automation Resource (index, create, show, update, delete)
- contact Resource