Operations
apiKeys.create can return a secret that is shown once. Never log it, paste it into public artifacts, or include it in agent transcripts beyond the minimum private handoff the operator requested.
CLI and MCP
Use the REST API or dashboard for key management. Hosted MCP hides API key operations; do not assumesearch("apiKeys") will return runnable operations.