Password
A secret, such as the API key of a service. The value is not shown on the screen.
In the editor

Besides the settings every field shares, a password field has:
| Setting | What it does |
|---|---|
| Placeholder | Grey text in the empty input. |
| Default value | The value the option gets when you save the menu, as long as it has no value yet. |
| Field style | The width of the input: Regular, Small, Large or Options. |
A password field has no Use in shortcode and blocks setting: its value is never shown on the website.
On the options page

The browser does not fill it in by itself (autocomplete="off").
The value
Stores the text, cleaned with sanitize_text_field().
The value is stored as plain text in the database, like every option. Anyone who can read the database, or a backup of it, can read the value.
In your code
$api_key = get_option( 'api_key' );