Currently the whoami tool requires you to set a bespoke x-mcp-authorization header. Instead we should use the visitor integration and fetch the key from the session token.
Initial installation of the extension should configure the integration, and the landing page should confirm that it is set and alert you to set it if not.