What’s the rational behind totally abandoning user API Tokens? Why not just make user API Tokens time limited in lifespan, like what was done with Jira / Confluence API Tokens? Are they really that evil?
Have you considered the effect on all those Trello automations that are dependent on API Tokens with the HTTP Request action to perform tasks? That part of Trello will need to be changed and every single automation on the planet that uses an API Token will need to be re-built.