API authentication uses scoped access tokens. Rotate production tokens every thirty days, store them in the deployment secret manager, and revoke unused credentials before changing indexing or retrieval permissions.
