Use the Partner API
The Partner manages OAuth2 credentials under API Credentials and keeps the secret exclusively on the server.

Authorized organizations appear under Authorized Clients, while delegated invoices are available under Partner Invoices.

Monitor processing under Job History and sensitive activity under Audit.

Continue with the Partner API and Bash workflow.