Temporary credentials shrink the theft window

A credential that expires in an hour is worth far less to whoever steals it than one that never expires.

That is the entire argument, and it is unusually clean. Long-lived keys copied into a script three years ago are still valid today and nobody knows where they all are. Short-lived credentials, issued on demand, turn a permanent liability into a brief one. The work is in the plumbing to issue them, not in the idea.

More on Passwords and secrets