Re: Tenant setup for lockbox - API or specific user credentials
Yes, we tend to recommend API users be used for Connect apps in general due to the possibility of user credentials changing or the user leaving the organization and temporarily stopping the app from running as expected. While this is a recommendation, it is not a requirement and your thought of using a standard user is completely valid but it leaves you open to the problems I highlighted.
You can also configure a user just for lockbox with limited access using the principle of least privilege to give the account the minimum required access to perform the expected functions.
Product Manager, Payments