Scope tokens to the action, not the identity
A common API-key mistake is issuing a token that means “this user” and then letting every endpoint decide what that implies.
Prefer tokens scoped to the action you intend: read invoices for tenant X, create deployments in project Y, rotate secrets for service Z. When the token is presented, authorization checks the declared scope first — before any role lookup that might expand privileges later.
Identity still matters for audit (who asked), but the blast radius of a leaked token should be the scopes on that credential, not every permission that identity holds in the admin console.
If you need a broader capability temporarily, mint a short-lived scoped token instead of widening the long-lived one.
