A gateway or service maps the key to an account, application, quota, or permission set. Keys are usually less expressive than user authorization tokens and should be scoped, rotated, and kept out of source code and logs. Transport encryption prevents exposure while the key is sent.