An API key is a password for the scopes it carries. Design storage, rotation, logging, and failure handling before issuing production credentials.
Phylex never needs your raw API key in a support ticket. Revoke and replace a key immediately if it appears in client code, logs, screenshots, or a repository.