Wouldn’t the low-entropy password still work on the web interface, and if so why is it an improvement? Any brute force attempts can very well be done on the web interface, and if there are countermeasures why can’t they be used on the API endpoints?
Then generate API keys on a per project reducing the attack surface in the case of breach?