test credentials should block, and not provide a way in.

Besides that, you could setup a special account set of test-accounts per api key.


[Linked Image from siemons.org]