Key handling
Treat API keys as secrets. Store them in your server-side environment or secret manager, never in a browser bundle.
- Create keys from the workspace integrations area.
- Use the bearer token only from trusted server-side jobs.
- Rotate keys when access changes or a secret is exposed.