API keys
Issue a key from Account → Developers, send it as a bearer token, revoke it when you are done. Scoped to one workspace, never to your login.
Stored as a hash and shown once. A key you can read back off a screen is a key that leaks with the screenshot.