Can you use the API key to control your funds without using the website that issued the key?
BLOODY YES ! That's the fucking point you don't get. you can access every function of a service via any computer terminal without the need of using the website. What kind of functions you can access is based on the api key privileges.
What I mean - can you use the API key if Bitmex (or whoever issued the key) is down? Your "terminal" still needs a server to connect to. Funny how the only definition of "website" that comes to your mind is the clicky-tappy one.
What you do after the being authenticated depends on what service/tool you are using.
If the "service" is kind enough to allow you to do that with the money they hold for you. Pretty much the opposite of what Bitcoin is - being your own bank
Of course a private key let you do different things than an api key of an exchange, but some of them are in common, that's why i keep saying that can act as.
An API key "can act" as a Bitcoin private key the same way like a rock "can act" as a computer as long as you use them as doorstops.