Any plans fo fix the bug that's just documented with a workaround? Surely the long term plan can't be to recommend setting a reminder every 80 days to reset the (unused) password so the account doesn't get disabled. There shouldn't need to be any password set at all on an API-Only user.