If the key may be exposed
Open Settings → API keys and revoke the affected key immediately. Requests using that key will no longer authenticate. Removing it from a repository or chat does not revoke it.
Replace a key used by an integration
Create a new key with the required permissions and scope. Update the integration’s secret, then make a test request. Once the new key works, revoke the old one.
If the old key has been exposed, revoke it first, even if this briefly interrupts the integration.
If you lost the secret
Create a replacement key. The key list shows an identifier for existing keys, not a way to recover the full secret.