There's really no practical alternative but to ship binaries with baked in API keys.
Maybe you dynamically provision API keys, but the binary needs a baked in permission to access that API to start with...
Maybe you dynamically provision API keys, but the binary needs a baked in permission to access that API to start with...