If you only need a Storefront token and not Admin API access, you don’t need Dev Dashboard or a custom app at all. Install the Headless channel from the App Store directly on that shop and click Create storefront, it generates the public and private tokens right there, no partner org involved.
Adding Headless is additional product management layer for store. They do not not need it. They need Storefront API token to query data for specific use case. This used to be so easy now is so hard. Do Shopify developer team know of KISS principal?
Fair complaint, but the Headless channel path is still entirely shop-admin side, no Partner org or Dev Dashboard needed. If it’s just the one shop you’re after, installing Headless and clicking Create storefront is the shortest route to the tokens right now.