The impact of a leaked key is low. The API key only allows someone to redeem vouchers on behalf of the retailers or retrieve historical voucher transactions. No sensitive privileges are allowed such as editing Merchant details (eg. Shop name and Bank account).