We only need to send two requests (Create API App and Auth account) and not need to open browser at Mastodon instance. We can also create API key using only browser. This way is very easy to use even who doesn’t know about Mastodon API. Mastodon also allow to edit permissions as you need on GUI.
To establish API access at misskey, we need to send at least three requests and open browser, which is very complex. We eager to use the default permission because less information of API.
I think the misskey developer just focus on UI. The authorisation system is very weaker than Mastodon. I don’t like this and this is the one of the reason I don’t use Misskey as home instance.