this is one is easy in the description it says that this lab has a horizontal privilege and if you read the academy content you would find out that is some thing like IDOR. and follow the same principle user can access to some thing that they is not for them, by changing the ID, so our target is every id in the web app.
when you logged in if you look in the url you can see this my-account?id=wiener, so the id is the username and our target is every ID, so lets change the ID to carlos , in url you most replace this my-account?id=carlos and then done you have the Carlos API Key.