It's not surprising, consider the failure modes:
- a key is made public, and we have to call a user or refund them (for retention purposes)
- a key is made public, and we revoked the key, potentially breaking the customers builds/deploys and potentially knocking a customers stuff out (if, for example, a key is disabled during a push to production).