Private keys
A private key is full control of the creator wallet. Treat it like a password that cannot be reset.
Onboard shows it only after you sign in with GitHub and confirm the warning. It is not stored in the page, not written to localStorage, and not cached. You can reveal it again later from the same GitHub session.
If you lose the key after you copy it somewhere unsafe, nobody can recover the funds. Import it into a wallet you already trust as soon as you reveal it.