Ah, sorry I misunderstood, @theo.benoit16!
In that case, you can remove the “Create/edit models and plugins” permission from their role:
Then they won’t be able to edit the schema. Your API key can have it own role that can do whatever is needed.
Does that do it?
