Use a unique password and enable two-factor authentication in account settings. Keep recovery information in a secure place and revoke sessions you do not recognize.
API keys can spend your wallet balance. Store them on your server, never in public browser code. Revoke a key immediately if it is exposed. Support does not need your password or authentication codes.
