Unpopular opinion: a plain API key in a header beat our fancy OAuth setup for our little internal tool
We had 3 devs and 40 endpoints pulling tokens and refreshing them, then switched to static keys scoped per service and cut auth bugs to zero in a month. Your mileage may vary on anything public facing, but does anyone here actually think token rotation pays off at that size?