I feel like we missed the chance to have a standard http resource for this stuff.

yes!

It's a shame, IMO, that the Basic Auth never got updated or superceded by something with a better UX and with modern security.