Isn't the idea you would have 2 factor auth on your account preventing any web brute force.
Then generate API keys on a per project reducing the attack surface in the case of breach?
Then generate API keys on a per project reducing the attack surface in the case of breach?