But how do you manage them in practice? At least with ssh everything is in one place in my .ssh folder. I suppose I could create a .tokens folder or somesuch.
The simplest thing is to create a ~/.netrc file:
machine foobar.atlassian.net login myuser1@mycompany.com password isudfiusldifuslkjhdflksjhdf
machine bitbucket.org login myotheruser password kjsdoihohuaoivhdifhuvoiadhf
machine github.com login companyuser1 password ghp_oisjdofhowuefoiusiofus
machine github.com login personaluser2 password ghp_jf9huiehuwfsouyewuhifuh
machine circleci.com login myotheruser password lkjdhiufwhu8ef7yw8yoefhozheofuhouha4lhlWiur
Clone a repository like git clone https://companyuser1@github.com/foo/bar.git and Git will load the right login automatically.I have no private key material or credentials in my .ssh folder (other than usernames and hostnames). All of my SSH private keys are stored in hardware.
Speaking of ssh key passwords: until OpenSSH 7.8 (2018-08-24), private keys using the PEM format were vulnerable to brute-force password cracking. You had to specify the -o option to use the more secure OpenSSH-format keys. Today the -o option is the default (and thus gone), but you might want to rotate your keys if they're from before September 2018.