I finally found my desired setup for passwords & tokens on my local machine.
(guess what, this is partially caused by recent events around npm, i don't want to have any token in my .bash/.profile/.config files. Period)
I don't want them also .in
.aws/credentials
.config/hcloud/cli.toml
~/.config/gcloud/
- this fortunately very short lived, but there is refresh token which is at valid next day (for several hours)- ... etc