Keys are the one thing you should never share or paste into a public thread.
- Store keys in environment variables or a secret manager, never in client-side code.
- Create a separate token per application so you can revoke one without breaking the others.
- Rotate tokens when a team member leaves or a key may have been exposed.
- If a key leaks, delete it in the panel immediately and create a new one. There is no penalty for rotating.
If you think your account was accessed without permission, contact support right away.