A broker can separate clients from powerful credentials

Rather than giving somebody the credential, give them a service that uses the credential on their behalf.

The powerful secret never leaves the broker, the request is recorded, and access can be withdrawn without rotating anything. It is how privileged access management works, and the same pattern applies to database access, cloud keys and administrative APIs.

More on Architecture patterns