Without the site ID, account-level calls are not enough
Your Wix account can hold several sites, and the connection has to know which one it works with. That is why the site ID is required; it is found in the Wix panel's address or on the site properties screen. The account ID is a separate, optional field — with the site ID filled in, it is not needed.
The API key is sent raw in the request header rather than used to produce a signature. That makes keeping it confidential more important. On the Stokzone side it is stored encrypted and never displayed again after entry.