Send the key
Include the key in theAuthorization header:
Limit scopes
Create one key per service and assign only the required scopes:Manage keys with a session
An API key cannot create, rotate, or revoke keys. These actions require a Customer session, an administrator role, and recent step-up.SimplePay returns a new key’s full value once. It stores an obfuscated
reference, not a recoverable secret.