Mixpanel's ingestion API at https://api.mixpanel.com records events; its query APIs read them back. EU projects use api-eu.mixpanel.com.
Sending events from a client needs only the project token, in the event body. Server-side import and queries use a service account with Basic auth — curl's -u, PostTaco's Auth tab. Both are under Project Settings.
Full reference: https://developer.mixpanel.com/reference/overview
The project token goes in properties.token.
curl -X POST https://api.mixpanel.com/track \
-H "Content-Type: application/json" \
-d '[{"event": "Signed Up", "properties": {"token": "{{MIXPANEL_PROJECT_TOKEN}}", "distinct_id": "user-123"}}]'
curl -X POST "https://api.mixpanel.com/import?strict=1&project_id={{PROJECT_ID}}" \
-u {{SERVICE_ACCOUNT_USER}}:{{SERVICE_ACCOUNT_SECRET}} \
-H "Content-Type: application/json" \
-d '[{"event": "Purchased", "properties": {"time": {{UNIX_TIMESTAMP}}, "distinct_id": "user-123", "$insert_id": "posttaco-1"}}]'