I've got great news everyone: you're now able to create API tokens scoped to specific (or all) buckets! All existing tokens will continue to work and will have access to all buckets. You can edit permissions for these tokens, or create new ones to limit them to specific buckets.
If you find issues with the authorization itself or the UI, please shout here! If you have other thoughts about the feature, please feel free to leave them in this thread.