For temporary use during security incidents. Could limit the damage because you can't get access to existing API tokens at the expense of temporary inconvenience to some users (but less inconvenience than putting the entire site in read-only mode, which is the only ability like this we have at the moment)