I think you're right about dnsimple tokens unless they've changed recently. I ended up writing a proxy that held the powerful token and then issued its own tokens to get around that... A bit convoluted
Annoying for dynamic DNS and DNS ACME challenges where you want a server to manage its own records and nothing else