Re: API Keys

Jan Algermissen <[email protected]>
Newsgroups gmane.comp.web.services.rest
Message-ID <[email protected]>
Hi Erlend,

On Nov 29, 2012, at 12:26 PM, Erlend Hamnaberg <[email protected]> wrote:

> Hi.
> 
> 
> Is there anyone with experiences with implementing API Keys in their apis?

If you are looking for something along the lines of OAuth Client identifiers, you should take a look at OAuth 1 and 2 and the associated discussions.

Eran IMO is the go-to guy in that space and you should get much out of his blog

http://hueniverse.com

and recent projects

https://github.com/hueniverse/oz

https://github.com/hueniverse/hawk (The README should provide a very good start).

Looking at Amazon IAM, as already suggested, is also good:

http://aws.amazon.com/documentation/iam/

Here are good intro docs from Google:

https://developers.google.com/accounts/docs/OAuth2

Personally, I am most excited about OZ, because Eran's OAuth 2 criticism looks very valid when you dig into it.


HTH
Jan


> 
> Putting the APIKey in the URI is obviously a bad idea as that leaks to every cache and intermediary. Including Apache logs.
> 
> So it must be a new header field. 
> 
> The problem with APIKeys as such is that they are spoofable, unless they are crypographically protected somehow, so my question is:
> 
> What do you do in your api?
> 
> 
> --
> Erlend
> 
> 
> ps:
> I am thinking about writing up an internet draft for a new Api-Key header field.
> 
> 



------------------------------------

Yahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/rest-discuss/

<*> Your email settings:
    Individual Email | Traditional

<*> To change settings online go to:
    http://groups.yahoo.com/group/rest-discuss/join
    (Yahoo! ID required)

<*> To change settings via email:
    [email protected] 
    [email protected]

<*> To unsubscribe from this group, send an email to:
    [email protected]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.