Authentication and key handling
The demonstration uses product-scoped APIM subscription keys. Send keys only in the Ocp-Apim-Subscription-Key header, never in URLs, screenshots, source code or chat.
Primary and secondary keys
To rotate a key, switch to the secondary, regenerate the primary, and verify that the old primary fails while the secondary and new primary succeed.
Automatic key expiry and rotation require additional automation.
Example tokens are not usable bearer credentials. Product keys do not protect against a user deliberately sharing a valid key.