API keys
An API key identifies whoever is holding it, which is not the same as identifying who you issued it to.
There is no further proof. Copied into a script, pasted into a ticket or leaked in a log, it works identically for anybody. They are convenient and they are bearer credentials with all that implies, which is why they need scoping, rotation and somewhere to be revoked.
Checked against the primary source.
