In Cloudflare Workers we like to represent things like this with "bindings". A binding is like an environment variable, except instead of containing a string, it contains a live object with methods that access the remote resource. Authentication is baked into this object, so the Worker code itself never has to see an API key at all. For example, if you have a Worker configured to use a KV namespace, you can write code like:
let value = await env.MY_KV.get(keyName);
No setup needed, at least in code. You create the binding either through the configuration UI or API.
So far we've mostly used this technique to connect Workers to other Cloudflare-provided services like Workers KV, but I'm super-interested in the idea of third-party bindings. Hopefully, you'd be able to configure them through an OAuth-like flow, where the Cloudflare dashboard redirects you to the third-party service, that service prompts you for permission, then redirects back to Cloudflare, and you never have to copy/paste a single secret.
Of course, under the hood this would all be backed up by strong authentication, but it's high time we stop making application developers waste time thinking about this stuff.
(I'm the tech lead for Workers.)