The key is not a password — it stands in for the username
PrestaShop's webservice key is used in an unusual way: in authentication it goes into the username field and the password is left empty. Someone unaware of this looks for "where is the password?" and finds nothing. On the Stokzone side all you do is enter the key; it is used correctly behind the scenes.
The key is generated in the PrestaShop admin under advanced parameters → webservice. On the same screen you should also make sure the webservice itself is enabled; while it is off, requests are rejected even with a valid key.