TL;DR this will allow dropping the API token as a repo secret, making use of OIDC to upload dists to PyPI and on top of that, said dists will get digital attestations that will also end up on PyPI.
Implementation instructions: https://packaging.python.org/en/latest/guides/publishing-package-distribution-releases-using-github-actions-ci-cd-workflows/