I'm curious why we are still messing around with all these tokens when we could be using asymmetric encryption, like Apple is using for their AppStore connect API https://developer.apple.com/documentation/appstoreconnectapi...
Just seems fundamentally more secure.