4 ms·
From my time browsing HN, the consensus seems to be "don't use JWTs". What is the preferred method of client authentication for simple APIs these days?
by jesseb 8y ago
From my time browsing HN, the consensus seems to be "don't use JWTs". What is the preferred method of client authentication for simple APIs these days?
- scient 8y agoOAuth access tokens? The difference being that JWTs contain information directly, as well as an access token to hit any APIs, while an access token contains no information on its own - thus solving the revocation issue. Now I don't think anyone really uses JWTs for API authentication, or they should not at least. APIs should still be gated by access tokens.
- deleted 8y ago[deleted]
- esotericn 8y agoDisclaimer: not a front-end dev. I'm not sure what the issue is with a simple session token, to be honest. OWASP have guidelines on this that cover the bases pretty well, I think. Store hashes, not tokens directly. Expire them server side. Don't accept user input (within reason). You generate and offer the tokens, you know what they look like, you can bounds check / sanity check appropriately. Perform some additional checks as necessary (e.g. invalidate a session if remote IP changes). If you have more security critical parts of the infrastructure, require re-authentication and more short-lived sessions for those. The obvious example would be how Amazon pretend you're "logged in" until you go to click My Orders, then you get auth gated. I tend to think that people over-complicate this stuff a lot as a premature optimization for scaling. A simple python script backed with some DB will do hundreds of hits a second to an auth service without really trying. If you need more than that, optimize. If you need more than 10k hits a second on a regular basis then you're probably at the point of hiring someone who knows this stuff. Just my 2c.
- detaro 8y agoTokens checked against server-side sessions. OAuth 2 is common to obtain them. (The tokens can of course be JWTs if you want their content to be transparent, but the key is to not rely on the metadata in the token alone for verification)
- mdpopescu 8y agoSession cookie, I believe.
- jpalomaki 8y agoHTTP basic authentication (of course over HTTPS)? Very simple to use and all the tools, such as curl, support it. It is used even by fairly large scale services like Twilio[1]. [1] https://www.twilio.com/docs/usage/api https://www.twilio.com/docs/usage/api