We can use JWT instead of user session AND instead of current implementation of api keys.  There are no specific suggestions. Should be discussed in the internal chat room.