Proving who is calling.
WHAT THE COMMON APPROACHES ARE
API keys Basic credentials Bearer tokens Token exchange with an authorisation server Mutual certificates Request signing
WHAT AN API KEY IS
A long secret string identifying the caller.
WHAT IT PROVIDES
Simplicity.
WHAT IT LACKS
Expiry, scope and any proof beyond possession.
WHERE IT SUITS
Server-to-server calls, over encrypted connections, with rotation.
WHAT BASIC CREDENTIALS SEND
A username and password, encoded but not encrypted.
WHY THAT IS ONLY ACCEPTABLE OVER ENCRYPTION
The encoding is trivially reversed.
WHAT A BEARER TOKEN IS
A credential where possession alone grants access.
WHAT THAT IMPLIES
Interception is complete compromise.
WHAT REQUEST SIGNING ADDS
Proof the request was not altered, and that the caller holds a secret without sending it.
WHERE IT IS USED
Payment and financial interfaces, commonly.
WHAT MUTUAL CERTIFICATES PROVIDE
Both sides proving identity.
WHERE THAT SUITS
Private integrations between known parties.
WHAT TO ALWAYS REQUIRE
Encrypted connections.
WHAT TO NEVER DO
Accept credentials in the address Accept unencrypted connections at all