Security Best PracticesNever expose API keys in client-side codeCreate a separate key for each projectEnable IP allowlistsSet daily budgetsRotate keys immediately after abnormal usage