Create
Configuration → General → API Keys. Name the key after the system that will use it.
Copy it now
The full key is shown once. Store it as a secret in the system that calls the API.
Rotate
Create a new key, move the integration to it, then revoke the old one.

Never put a key in a browser or mobile app. For browser calls, create the session on your server with Create web call.