Plaid's API runs on https://sandbox.plaid.com for testing and https://production.plaid.com for live. Every call is a POST, and the client id and secret go in the JSON body, not in headers.
Copy your client id and sandbox secret from the Plaid dashboard. In the examples they're written {{PLAID_CLIENT_ID}} and {{PLAID_SECRET}}. Most data calls also need an access_token for a linked account.
Full reference: https://plaid.com/docs/api/
The token your front end uses to open Plaid Link. Body from Plaid's quickstart.
curl -X POST https://sandbox.plaid.com/link/token/create \
-H "Content-Type: application/json" \
-d '{"client_id": "{{PLAID_CLIENT_ID}}", "secret": "{{PLAID_SECRET}}", "client_name": "Plaid Test App", "user": {"client_user_id": "user-1"}, "products": ["auth"], "country_codes": ["US"], "language": "en"}'
curl -X POST https://sandbox.plaid.com/institutions/search \
-H "Content-Type: application/json" \
-d '{"client_id": "{{PLAID_CLIENT_ID}}", "secret": "{{PLAID_SECRET}}", "query": "chase", "products": ["transactions"], "country_codes": ["US"]}'
curl -X POST https://sandbox.plaid.com/accounts/balance/get \
-H "Content-Type: application/json" \
-d '{"client_id": "{{PLAID_CLIENT_ID}}", "secret": "{{PLAID_SECRET}}", "access_token": "{{ACCESS_TOKEN}}"}'