Short answer
HubSpot's developer docs: apps installed in one account use static auth access tokens; apps for many accounts need OAuth. A separate developer API key lives in the developer overview and is only used where an endpoint's docs say so, in the hapikey parameter.
1. In HubSpot
The relevant screen in my demo portal.

2. Worth knowing
Treat tokens like passwords: never put them in front-end code.
3. Related
Private apps moved to Legacy apps.