Earlier quoted context omitted.
Do you have any examples ? It's the first time I hear about replacing API keys
OAuth with refresh tokens. IAM roles/workload identity. Even time-limited or signed JWT, though has a separate issues. Maybe you'll say 'those are both just text values passed like an apikey' though api keys don't frequently rotate/time limited, which is an important security feature.
Then the LLM slurps up your refresh token. What's next?