Zendesk Support's API lives at https://<subdomain>.zendesk.com/api/v2.
With an API token (Admin Center → Apps and integrations → Zendesk API), Basic auth uses <email>/token as the username and the token as the password — curl's -u, PostTaco's Auth tab. {{ZENDESK_SUBDOMAIN}} is the part before .zendesk.com.
Full reference: https://developer.zendesk.com/api-reference/
curl "https://{{ZENDESK_SUBDOMAIN}}.zendesk.com/api/v2/tickets.json?per_page=10" \
-u {{ZENDESK_EMAIL}}/token:{{ZENDESK_API_TOKEN}}
curl "https://{{ZENDESK_SUBDOMAIN}}.zendesk.com/api/v2/search.json?query=type:ticket%20status:open" \
-u {{ZENDESK_EMAIL}}/token:{{ZENDESK_API_TOKEN}}
curl -X POST https://{{ZENDESK_SUBDOMAIN}}.zendesk.com/api/v2/tickets.json \
-u {{ZENDESK_EMAIL}}/token:{{ZENDESK_API_TOKEN}} \
-H "Content-Type: application/json" \
-d '{"ticket": {"subject": "Created from PostTaco", "comment": {"body": "Testing the API."}}}'