You can't leak API keys if there are no API keys to leak! The article recommends OIDC for apps, which is a step up, especially if you rotate the bearer token, however there is another option - use short-lived certs.
Our project Machine ID is replacing API keys with short-lived certificates:
https://goteleport.com/docs/machine-id/introduction/
Another great option is SPIFFEE https://spiffe.io/
The adoption is slower than we wanted, because it's not trivial to replace API keys, but we see more and more companies using mTLS + short lived certs as alternative to shared secrets.