Secrets are API keys. They authenticate HMAC requests (X-Makaira-Nonce / X-Makaira-Hash). Older name: Shared Secret. The original shop Connect key is stored with description legacy secret.
Keys start with api_. The full value is returned as plainSecret on create, and on GET only if the caller holds all permissions assigned to that key. Otherwise you see maskedSecret only.
Permissions on keys use colon API notation (importer:write, persistence:write). Presets (Makaira-Preset.Importer, .Search, .Shopify) apply a bundle of those permissions so a new key can replace the legacy shop secret.
UI guide: API Keys. HMAC: Authentication.

