Generate the hidden service key on the server where it will be used, not on a laptop or development machine. Generating on the production server eliminates the risk of the key being copied during a transfer operation. When Tor generates the key, it uses the operating system's cryptographically secure random number generator (/dev/urandom on Linux), which is appropriate for production key generation.
If the operational requirement is to generate the key on an air-gapped machine and then transfer it to the server (for organizations with strict key generation policies), use a machine that has never been connected to the internet, generate the key using mkp224o or by running Tor in isolation, and transfer via USB with full disk encryption after verifying the air-gapped machine has no network capabilities.
After initial key generation, read the onion address from /var/lib/tor/hidden_service/hostname and verify it matches your expected format (56 characters, ending in .onion). Store this address separately from the key itself. The address can be shared publicly; the private key files must never be shared or transmitted in plaintext.