Key id explicitly allowed for a granted API client app.
Surrogate primary key.
Master key id the app may use for crypto operations.
Owning app package (foreign key to ApiAppEntity).