maskApiKey function
Masks apiKey for display, keeping only a known sb_*_ prefix and the
last 4 characters, e.g. sb_secret_…AbCd.
Implementation
String maskApiKey(String apiKey) {
final prefix =
RegExp(r'^sb_(secret|publishable)_').firstMatch(apiKey)?.group(0) ?? '';
final rest = apiKey.substring(prefix.length);
if (rest.length <= 8) return '$prefix…';
return '$prefix…${rest.substring(rest.length - 4)}';
}