API keys
API keys authenticate REST API and MCP access (Authorization: Bearer <key>). The plaintext is shown exactly once at creation — store it safely; revocation takes effect immediately.
New key created — shown only this once:
If your email isn't verified yet, this key can't call the render endpoint until it is; resend the verification email from the render page.