Hi!
When things go wrong in an external system which makes requests to hrflow, it's important to be able to act fast.
So I suggest to have an endpoint where you can automatically revoke the API key used to call the endpoint. This would make it possible for systems to minimize costs and damage when for example a DDOS attack happens or malicious user gets access to a system.