How do ephemeral client tokens protect API keys in browser games?
Never send your real API key to the browser. Your server holds the key and mints a short-lived ephemeral token per session; the game's client-side JavaScript uses only that token, which expires quickly and limits damage if it leaks.