The intention is for them to have no access to or knowledge of file contents. Since the key is the URL, and URLs are generally sent to the server by the browser, Mega could (presumably) get the keys when someone follows the download link.
I believe removing the key from the URL still works, the site just prompts for it when needed, but that could also make its way to Mega if they ever decided they wanted it. It seems like a decent approach for ease of use, but has some weaknesses if security is the main goal. Encrypting separately before upload is still a very good idea if it matters for whatever reason.