ACCOUNT
Protect programmatic access
Treat an API key like a password for automation.
Create only when needed
Do not create extra API keys that have no purpose.
Keep private
Never place API keys in public repositories, screenshots, browser client code, or public messages.
Rotate exposed keys
If a key is exposed, replace it rather than continuing to use it.
Least privilege
Use the narrowest supported access required by the integration.