That would give us access to the users account at any time. It seems requiring their password be sent with every request is more secure (over https, of course)
I could have multiple keys, all w/ different access levels, all on the same user account. There is no way to do this with a password, other than to just have separate user accounts.