The docs suggested the key name was optional, but it was required in practice. The maintainer identified the bug and fixed it in Portman v1.22.0: upgrade and the API key survives the overwrite even when you only change the value.

Context: GitHub issue on apideck-libraries/portman: using overwriteRequestSecurity in variation tests to change the apiKey value, but without including the key name, silently removes the API key from the generated Postman collection.