PostHog Cloud has two hosts: https://us.i.posthog.com ingests events with your project's public key, and https://us.posthog.com/api is the private API. EU projects use eu. hosts.
Capturing events needs only the project API key (public, starts phc_), in the body. Private reads need a personal API key as Authorization: Bearer <key>. In the examples they're {{POSTHOG_PROJECT_KEY}} and {{POSTHOG_PERSONAL_KEY}}.
Full reference: https://posthog.com/docs/api
curl -X POST https://us.i.posthog.com/i/v0/e/ \
-H "Content-Type: application/json" \
-d '{"api_key": "{{POSTHOG_PROJECT_KEY}}", "event": "signed_up", "distinct_id": "user-123"}'
curl -X POST https://us.posthog.com/api/projects/{{PROJECT_ID}}/query/ \
-H "Authorization: Bearer {{POSTHOG_PERSONAL_KEY}}" \
-H "Content-Type: application/json" \
-d '{"query": {"kind": "HogQLQuery", "query": "select event, count() from events group by event order by count() desc limit 5"}}'