mbn_test_ or mbn_live_. The full secret is revealed once and is never stored in recoverable form.
Production checklist
- Create one key per service and environment.
- Grant only the required permissions.
- Restrict models and endpoints when useful.
- Store the key in a server-side secret manager.
- Set an expiry for temporary access.
- Rotate before revoking an active key.
Rotate without downtime
1
Create the new key
Create a second key with the same settings and store it in your secret manager.
2
Deploy it
Roll the new key out to your service and confirm requests succeed.
3
Check the old key is idle
Watch Last used on the old key until it stops changing.
4
Revoke the old key
Revoking takes effect immediately, and the action is written to the audit log. Requests that still use it receive
401 with revoked_api_key.Creating keys is rate limited (30 per hour per user), so plan bulk key creation instead of scripting it in a tight loop.

