API keys are the right fit for server-to-server APIs where full OAuth is overkill. Three ways to enforce one in ASP.NET Core - middleware, an MVC filter, and a minimal API endpoint filter - and when each fits.
Put roles in the JWT, seed them with Identity, and gate endpoints with RequireRole - plus refresh tokens in HttpOnly cookies so the whole flow works from a browser.
Wire ASP.NET Core Identity's built-in API endpoints to an Angular app - login, a bearer token on every request, and an HTTP interceptor that silently refreshes an expired token and retries the failed call.