Settings > API keys > New. Name the key (we will show this on every request log line), pick the scopes, click Generate. Copy the key; we show it once and never again.
Scopes
Pick the narrowest scopes that get the job done. read:conversations, write:conversations, read:contacts, manage:webhooks, etc. Full list at /developers/get-started/authentication.
Rotate
Rotate quarterly at minimum. Old key stays valid for 24 hours after rotation to give you a window to update consumers.