Do not share one unrestricted key

A single key copied across laptops, CI jobs, and agent environments is difficult to rotate and impossible to attribute cleanly. Team access should be scoped so one compromised credential does not affect every workload.

A practical team setup

Start with separate keys for local development, automation, and production-like workloads. Add team members with the minimum role they need, then set budgets that match each environment.

  1. Create a team and invite the people who need access.
  2. Issue team-scoped keys for distinct environments or agents.
  3. Set daily token budgets before broad rollout.
  4. Review usage by key and rotate credentials on a regular schedule.

Use visibility to improve policy

Usage data is most useful when it can be tied to a team, key, client, and routing mode. That context helps owners find expensive workloads, tune defaults, and separate expected growth from accidental spend.

The result is controlled access without forcing every developer to operate provider accounts or maintain a separate routing configuration.