Header-only, never stored
Your Replicate key arrives in a request header and lives in memory for exactly one request — long enough to bridge the completion webhook, then it's wiped. There's no database column for it, encrypted or not. We have nowhere to keep it.