API CREDENTIALS

Keys need scopes, ownership, expiry and rotation.

V11 introduces a concrete credential lifecycle rather than treating API access as a single permanent secret.

Environment

Sandbox and production credentials are separate.

Scopes

Keys receive only the endpoints and actions they require.

Rotation

Issue, overlap, revoke and replace credentials safely.

Usage

Associate calls with organisation, key, endpoint and request ID.