Knowledgebase

API Authentication Methods Print

  • 0

Proving who is calling.

WHAT THE COMMON APPROACHES ARE

API keys Basic credentials Bearer tokens Token exchange with an authorisation server Mutual certificates Request signing

WHAT AN API KEY IS

A long secret string identifying the caller.

WHAT IT PROVIDES

Simplicity.

WHAT IT LACKS

Expiry, scope and any proof beyond possession.

WHERE IT SUITS

Server-to-server calls, over encrypted connections, with rotation.

WHAT BASIC CREDENTIALS SEND

A username and password, encoded but not encrypted.

WHY THAT IS ONLY ACCEPTABLE OVER ENCRYPTION

The encoding is trivially reversed.

WHAT A BEARER TOKEN IS

A credential where possession alone grants access.

WHAT THAT IMPLIES

Interception is complete compromise.

WHAT REQUEST SIGNING ADDS

Proof the request was not altered, and that the caller holds a secret without sending it.

WHERE IT IS USED

Payment and financial interfaces, commonly.

WHAT MUTUAL CERTIFICATES PROVIDE

Both sides proving identity.

WHERE THAT SUITS

Private integrations between known parties.

WHAT TO ALWAYS REQUIRE

Encrypted connections.

WHAT TO NEVER DO

Accept credentials in the address Accept unencrypted connections at all


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot