People, service accounts and their own keys
Every request is made by someone: a person, or a service account for CI and scripts, each with API keys of their own.
- Keys are stored as hashes, shown once, may expire, and are revoked rather than deleted
- The first administrator comes from one setting or one command
- Everyone else is managed over the REST API or the CLI