Re: API Keys
Will Hartung <[email protected]>
| Newsgroups | gmane.comp.web.services.rest |
|---|---|
| Message-ID | <CAA2iDiCfPTWwhJnuQt--eapoUwBHhk1YT+oyw+L6kmo9YwAorA@mail.gmail.com> |
Go look at Amazon Web Servuces and how they do this. They address thus and it's well documented and there are client and even some server side open codes you can use. AWS does most everything folks want and they've put some thought into it. On Thursday, November 29, 2012, Erlend Hamnaberg wrote: > ** > > > Hi. > > Is there anyone with experiences with implementing API Keys in their apis? > > Putting the APIKey in the URI is obviously a bad idea as that leaks to > every cache and intermediary. Including Apache logs. > > So it must be a new header field. > > The problem with APIKeys as such is that they are spoofable, unless they > are crypographically protected somehow, so my question is: > > What do you do in your api? > > > -- > Erlend > > > ps: > I am thinking about writing up an internet draft for a new Api-Key header > field. > > > -- CONFIDENTIALITY NOTICE: The information contained in this electronic transmission may be confidential. If you are not an intended recipient, be aware that any disclosure, copying, distribution or use of the information contained in this transmission is prohibited and may be unlawful. If you have received this transmission in error, please notify us by email reply and then erase it from your computer system.