1
Separate secrets from source code
Load the API key at runtime from an environment variable or managed secret. Keep local configuration out of version control, review ignore rules, and use different credentials for development, staging, and production whenever the account structure supports it.