Keys use ani_test_<identifier>.<secret> or ani_live_<identifier>.<secret>. The lookup identifier is public. The secret has 256 random bits; the database stores a SHA-256 hash of the whole key.
The key is returned only on creation, with Cache-Control: private, no-store. Subsequent reads return metadata only. An application can have up to 100 issued keys, including revoked keys.
Keys support a name, scopes, optional expiration within two years, approximate last use and revocation. To rotate, create a new key, update your integration and revoke the old key.
Do not automatically retry key creation after a timeout. Check metadata, revoke any orphaned key and create a replacement. Issuance is not idempotent.