API keys
Live or test, read only or read and write
Two choices are made when a key is created in Settings > Developers, and neither can change afterwards. A different answer is a new key.
Live or test
Read only or read and write
No key can move money. Payments, refunds, orders and gift card balances are read only, whatever the key. A read only key that writes gets a 403 forbidden.
A key cannot change or clear an email or phone number a customer already has - that is a 409, and the customer changes it in their portal. An empty one can be filled.
One key per integration
Give every system its own key, named after it. Then revoking one stops exactly one thing, and the last-used time on each key says which are still in use. A workspace holds at most 25 keys.
Who a write names
A key acts as its own member of the workspace. A customer it creates is recorded as created by that key.