# [API keys & security](https://rebilder.com/help/api-keys)

- [How API keys work](https://rebilder.com/help/api-keys/how-api-keys-work)
  - Keys start with rblr_, are shown once, and authenticate supported integrations for your own store. Learn their scope and how to rotate them.
- [Rotate a key](https://rebilder.com/help/api-keys/rotate-a-key)
  - Generate the replacement in Settings; the new key exists before the old one is revoked, so your store is never left keyless.
- [What to do if a key leaks](https://rebilder.com/help/api-keys/key-leaked)
  - Rotate immediately, then know the blast radius: a leaked key can access supported integrations for its store.