API keys can carry permissions such as campaign read, campaign write, and statistics read access.
Create separate keys for separate applications when practical. This makes it easier to revoke one integration without disrupting another.
If an API key is exposed, revoke it immediately and create a replacement. Never send an API key through public support posts, screenshots, or client-side code.