Use API tokens.
That'd be a good idea in general - as they can simply be disabled/removed if really compromised without affecting your root account. Further, they must be given explicit permissions (they do not inherit the one from the user by default), which allows to restrict them to the really necessary.
Use API tokens.
That'd be a good idea in general - as they can simply be disabled/removed if really compromised without affecting your root account. Further, they must be given explicit permissions (they do not inherit the one from the user by default), which allows to restrict them to the really necessary.