Create an API key that can only do what its job needs. A key for your checkout service can send email and read templates, and nothing else, so a leaked key has a small blast radius.
await samva.apiKeys.create({
name: "Transactional sender",
access: { mode: "restricted", resources: { messages: "write", templates: "read" } },
});
Every key is also capped by its owner's current role. Demote the owner and the key loses that access on the next request; remove the owner and the key stops working.
Authentication lists the resources you can grant.