Auth identity for client creation functions.
The caller's JWT, or `null` for anonymous access.
Name of the API key to use. Falls back to `"default"`, then first available.