The benefit of api tokens that can quickly be created and destroyed are that they are short lived, and less likely to be compromised. The vault product could create the temporary token and it would exist only for the amount of time needed for a job to finish it's work and then no longer exist. A job could perform any meraki configuration through the api. Even if we just had an API call to create and delete the API tokens for an existing user would be a small step to work towards this. It is inconvenient to have to come up with email aliases for a 'service account' that a human would never use, but not a show stopper to work towards short lived tokens.
... View more