So, with past dramas, I figured this might be a question to raise and thrash out so we can have a sensible discussion about how to approach in a way which will eliminate drama or potential problems.
I have wanted to, for a while, simplify the user sign-up experience to tools I run such as FFScouter. Requiring them to visit the website and manually copy/paste keys is a bit of a pain and prone to errors, and just doesn't make for a great user experience. So, the idea of an automatic/API-based sign-up to integrate with existing services has been in my view for a bit. But I am wary of past misunderstandings given I sometimes don't appreciate/understand how non-tech folk might comprehend the processes or I may not understand their assumptions.
The rules already have a section for integrations, seen below:
"When integrating your service with another service (opt-in), make sure there's at least a link to ToS of the service you're allowing the user to integrate with.
When integrating your service with another service (automatically), your ToS need to cover the usage of the service you're integrating with."
So, if my understanding is right, a third party script is able (if I built it) to opt-in or "share" an existing API key to another service. I think that from a rule perspective is already clear-cut.
Where I have more concerns, is tracing the origins of this in various ways and accountability. I label all FFScouter requests to the Torn API which originate from a single static IP, and logs are kept for a while to help trace the origin of signups. However, this is no guarantee somebody will not assert that their API key was misused as I have no control over third party scripts or services to ensure they are ToS compliant, if I enabled an API-based signup mechanism.
Open to all ideas on what mechanisms we could look at to enable a more seamless sign-up experience between services, without also opening up to the risk of abuse. I think the actual number of abuses are quite low and niche in this scenario, since it assumes somebody must already have an API key to misuse, but scope for misunderstanding is wider where a script out of our control might present the integration in an undesirable way.