Two things need to happen.
  1. Multiple api keys. Let us create multiple. Now we can only create one api key at a time, and when we need the key, we need to rotate the old one, which breaks existing automations, forcing us to replace it everywhere it was used.
  2. Per key permissions: read, write is a bare minimum, otherwise more granular, like creating tasks, comments, deleting, etc.
  3. Ability to read older keys. Ofc this one's optional, but maybe you can make old keys readable only if they are not "full permission" or if they are with read-only permissions.
I'm surprised this is not a bigger request.
The MCP does not do the job the same way the API does, we need proper API access and as far as I see now there is no traditional multiple key management.
Maybe you can put these things behind a warning if security is the fear