Add an API comments section in the api call. This will help with debugging what programs are what from a community dev's perspective.
There is a false sense of security if the comments is slapped with the words "DoctorN", and so the comments probably should be hidden away so that only devs can find it. Probably the lowest barrier of entry would be requiring opening the dev console, maybe seeing the not displayed comment in the html using display:none. Or maybe hiding the comment in the JSON of the preferences.php?ajax=getApiData (similar to how the id of faction news is hidden in the json as well).
PART 2: API VERIFICATION - SERVER BASED APP SECURITY
Add the ability for a community dev to opt into obtaining a separate "dev key".
This key is designed to authenticate the dev's SERVER BASED APPLICATIONS as applications that the dev has full control over (and while it's not suppose to be a sign of trustworthiness, it's a sign of "this is the definite user who is accessing your data."
Conclusion
These two combined should help with both debugging (especially userscripts) as well as provide some level of authentication for server based applications (so that remote IP addresses are demystified).
I don't get the API comments either. I think the API logs should just show the user-agent string of the client requesting the API data. Maybe on hover so that we can figure out who is making API calls frequently with our keys.
In addition to this, something like an official torn proxy tool would be amazing. Where we could generate app specific keys with specific data permissions. I am sick of giving a bunch of people full access to a ton of my account data just so I can get access to useful tools to help in Torn.
Comments are for when the abusive api system is your own network, but u don't remember what tools u installed / u don't remember what tools u wrote.
Combined with verification, it (if visible to the public) can also help users [relax/be on guard] and understand why their API is being used by a certain dev user.
On the subject of verification:
As long as the user can't reverse engineered the dev secret, then we are good. Similar to Oauth2, but without the client auth.
On the subject of security:
Ched has already declined more complexity to the user's end (with comments against multi key system, making the API too convoluted to the normal user). I do not want to open this can of worms, but if our community is strong, then we can probably get Ched to change his mind. This is NOT the direction of this suggestion just yet: baby steps.
We have way too many drivers in this one car. And so we need pseduo logs of who drove the car. Even if the logs can be forged. If logs are being forged, then it's time to reset the key.
I come into a new environment, and i see someone hammering their own api. i do the best i can to salvage the situation by telling the user to turn off everything... but that 1 call is still happening.
I am no idiot developer. But there are idiot developers out there. So this acts as a catch for those idiot developers (i am looking at potentially the torn widget, cuz I'm hearing bad things about that app)