API key rules
- Create one key per website or integration.
- Rotate keys after staff or vendor changes.
- Remove unused keys.
- Use allowed domains when you want origin checks.
Origin checks
If a key has allowed domains, Replied accepts browser submissions only from those origins.example.com.