Cloudflare API Tokens and Zero Trust

I had found some comfort in using “Client IP Address Filtering” with my Cloudflare API token to reduce risk in case the token were compromised. I’ve now started using Cloudflare Zero Trust with WARP, which I like for the security benefits that it provides; however, it makes the API token client ip filtering far more difficult to continue doing unless I were to allow all Cloudflare IPs in the token config or disable WARP every time I go to make an API call with my token.

Are there any recommended ways to harden Cloudflare API tokens with the Cloudflare Zero Trust product?

