> You can restrict access to external APIs in a more fine grained manner
I've done this very successfully for many APIs before. I've found weird things among providers where using AWS (or GCP or Azure) gives you crazy fine-grained access controls (which are great after you spend two days figuring out how to use them well), but, some of the low cost competitors have core services that work just as well but their APIs are entirely binary (either you have full access, or none) but by adding a thin API layer above that you can enable all sorts of useful things. Provider doesn't support R/O API keys for terraform plans? Just run a proxy which enables that. Provider won't allow you to give someone an API key which can only reboot VMs, but, not delete them? Just write a proxy which does.
Very powerful model if you adopt it well.