For me it was the fact that it did not work without third party cookies.
So the irony is that we make our API calls digitally signed (more secure) but to do so from the context of a bookmarklet you have to enable 3rd party cookies because browsers bundle that switch to the capability that we really need (i.e., there is no "enable loading of cross domain iframes that can read client local storage securely" option because its unfortunately pairs with 3rd party cookies).