Thanks for the feedback! This is an area I've gone back and forth on. Originally I didn't want to accept a user/password as I realized many wouldn't trust this. Without allowing it, I was worried I'd lose people that have never used API keys before. The hope of the video link below the 'Let me have it' button showing how to make read only keys was that people would trust that they could give me a set of keys that allowed restrained access. In addition, the read only keys created could be deleted immediately afterwards if it was of concern.
Any thoughts on how I could better communicate this + build trust with users in this setting?