Key handling
- Treat Recurr API keys as secrets
- Store keys server-side only
- Use separate keys for test and production where available
- Rotate keys if exposed
- Do not embed keys in mobile apps, websites, or public repositories
How customer systems authenticate to Recurr event and export APIs.