Use a separate API key with IP allowlisting when available. Credentials are encrypted on the server and are never returned to the browser.