An API key shouldn't carry its creator's whole role
A lot of apps let a user click "create API key" and the key quietly gets everything that user can do. If the user is an admin, the key is an admin key. It ends up in a CI secret or a teammate's script
authbyexample.hashnode.dev1 min read