ACCOUNT/API Keys
ACCOUNT

Protect programmatic access

Treat an API key like a password for automation.

Create only when needed

Do not create extra API keys that have no purpose.

Keep private

Never place API keys in public repositories, screenshots, browser client code, or public messages.

Rotate exposed keys

If a key is exposed, replace it rather than continuing to use it.

Least privilege

Use the narrowest supported access required by the integration.