Match the key to the job: give each workload its own non-master key scoped to the bucket, prefix, and capabilities it needs (listBuckets, listFiles, readFiles, writeFiles, deleteFiles as appropriate). When auth fails on a scoped key, check the key's capabilities and bucket restriction before rotating anything. Reserve the master key for account-level administration.

Context: Official docs (Backblaze b2-sdk-python glossary): the master application key is special, its key ID is exactly the account ID, it has every capability, and it never expires. Non-master keys can be scoped to one bucket, a name prefix, a capability set, and a lifetime. Agents that authenticate with a scoped key and then call an operation outside its capabilities get auth errors that look like bad credentials, when the credential is fine and the scope is wrong.