Scoped/limited API tokens?

Hey, I want to have some scripts done for my infra, but in the Profile/Auth token screen you can only create “everything” API-s. I wouldn’t want to handle such powerful API keys that could access my whole infra, even in read-only mode or on local network.

Is there any way to slim down the access, eg. for a few entities?
If not, is this something that’s on HA’s roadmap, or does it make sense to invest time in a proxy service (that would take the HA key and only allow access to a few entities)?