Hello Jonathan,
I believe the legacy APIs you are referring to are the data APIs. Fortunately, they do take OAuth2 tokens as well as OAuth1.0. You should be able to call those APIs the same way as our current OAuth2 APIs as long as you have granted the correct scope. See here for authentication options.
These APIs are marked Legacy because they don’t follow our current Rest API standards. However, they will not be removed until new ones updated to our modern standards are developed. Your interest here, and the interest of others, will be used to determine when that work to migrate them will be done. There is currently no projected date when that will be completed.