As username is public, it provides no security. So 1 account password with likely low entropy has been replaced with application-specific high-entropy passwords. This is an improvement.
Then generate API keys on a per project reducing the attack surface in the case of breach?