API keys
Service-to-service or low-complexity access with explicit scope and rotation.
Scope, rotate, revoke and observe API credentials; use stronger identity flows when user or organisation delegation is required.
Scope, rotate, revoke and observe API credentials; use stronger identity flows when user or organisation delegation is required.
Service-to-service or low-complexity access with explicit scope and rotation.
Delegated user/organisation access where appropriate.
Least-privilege resource/action permissions.
Creation, last-used, expiry, rotation and emergency revocation.
Request IDs, actor, scope, rate and error monitoring.
Never expose server secrets in client-side code or public repositories.
Production integrations require scope, identity, data classification, rate and support requirements.