Started locking down our API keys with IP allowlists, but a client on a cruise ship got blocked for 4 days
Now I'm stuck between strict allowlists that break real users and rotating tokens with short expiry that cause constant 401s. What are you all doing for key security without torching the customer experience?