Shared API keys give coarse identity

One key used by several systems or people means you cannot tell which of them did anything.

Revoking it breaks everybody, so it never gets revoked. Attributing an action is impossible, so misuse cannot be traced. Per-consumer keys cost a little more setup and are what make both accountability and containment possible.

More on API security