Instead of using a username/password, your script sends the token in the request header:
master_user admin password = "hashed_value"; allow = "192.168.1.0/24";