WTH can't I set permissions on a long-lived access token?

I would LOVE to use long-lived access tokens. But those grant permissions for my whole HA. And I’m not exactly comfortable leaving such a token somewhere on a server (even if it’s my VPS) or even in a third-party app (like Apple health export). It would be great if I could only let a token access certain entities. And r/w/rw permissions would also be nice.