Local API and website accounts
Website sign-in, desktop pairing and local API authorization are separate mechanisms.
Keep credentials separate
A website password or device token is not a Local API bearer token. Create the latter inside the desktop app. Optional desktop pairing links the intended device to a website account; profile control is a separate opt-in. The website cannot operate a closed or offline desktop.
Data and plan boundaries
With the separate profile-control opt-in, pairing shares profile IDs, names and runtime states and permits start/stop requests. It is not cloud profile storage or a cookie/password/fingerprint backup. This API documentation makes no Free/Premium entitlement, capacity or pricing promise. Check the installed feature state and current published plan information independently.