Held by this page's HTTP client (window.myBrowserHttp), which
performs JRock's requests and adds the Authorization header
itself - the key is never handed to the in-browser JVM, and never sent
anywhere except directly to the Bedrock endpoint. You can change the key at
any time; the region is picked up by JRock when it starts, and after that
can be changed in JRock's own Configure dialog. A short-term key (tied to
its region) can be generated in the
AWS console.