We really should not be storing bot API keys in the DOM and should require some sort of additional authentication before showing them, but this seems reasonable for a first pass. (imported from commit c7d75aa52e21894bf53917457e771c18de38bbcc)