Ask HN: How do you enforce least-privilege when an API token has full access? | Dark Hacker News