Thinking of standards from cPanel and other control panels out there, which use an auth hash to grant access to the API, which can then be stored in billing systems rather than a plaintext password.

Anything that makes it harder for someone to compromise a system is worth considering in my opinion!
This is absolutely on the map for a future version.  In fact, the current API was designed back in 2006 and is showing its age at this point... we're experimenting with a framework for a new REST API which, when it's ready, will definitely do away with password authentication for API calls.
Would LOVE to see this as well Steve.
