We make a lot of automation webhook calls from our apps, and a Forge/REST API to call directly would be very helpful for us as well.
Even better if they find a way to not need the customers to copy paste and for us to encrypt and store a token. The trigger automation rule should just need the rule ID. If the calling app is already authenticated as inside the site then the token is redundant.
+1 for us.