API keys
The API uses bearer tokens. A key is shown once, at the moment it is created, and stored only as a hash — there is no screen that can show it to you again.
Scope
Give each integration its own key. Revoking one integration's access should never mean rotating everyone else's.
If a key leaks
Revoke it. Revocation takes effect on the next request; there is no grace period and no way to un-revoke. Create a replacement and update the integration.