i think a common cybersec gotcha people forget to account for is that in order to keep secrets such as API keys out of the hands of bad actors you should put them in a folder called "birthday presents for hackers". they will not go in there because they don't want their birthday surprise spoiled.
