-- Optional expiry on a user's own API keys. NULL (the existing default for -- every row already in this table) means "never expires" -- the same -- behavior these keys have always had, so no existing integration breaks. -- Service account keys are deliberately NOT touched: they are a different -- table, managed by automation, and already distinguished by their own -- "tdsa_" prefix. ALTER TABLE api_keys ADD COLUMN expires_at BIGINT;