You can also generate multiple keys, so if one app misbehaves, you don't need to rotate all the keys, just the one that misbehaves.
This is assuming the API keys can only do generation. If it can access billing details or something it's very different of course.
Because it's bad practice to provide sensitive information to untrusted sources, and if you are an ethical developer, it's an anti-pattern to write software that encourages bad practices.
Your credit card company will reverse any authorized charges. Will you email me all your credit card info?
I answer back to myself: I miss-understood since the idea of the developer is to run it locally http://localhost:3000 while I got scared from the DEMO
Congrats to the developer!