3 ms·
would you secure api via JWT? Session token are not an option, basic auth can be an alternative.
by esseti 7y ago
would you secure api via JWT?
Session token are not an option, basic auth can be an alternative.
- abathur 7y agoI wouldn't call it a best-practice, but I've done this. I guess my basic heuristic is that it's decent for an API that you expect to have very few consumers (internal, partnerships), but I would hesitate to recommend them for an API aiming for wide adoption.
- user5994461 7y agoJWT works well. Securing API is one of its main use cases. That being said. Please do NOT use basic auth for anything in 2020. This is the worst anti-pattern one could do for authentication. Basic auth simply transmits the username and passwords in clear text with every request. No application should be receiving username and password in clear text besides a single auth service. The passwords will get leaked all over the place between developers debugging, verbose logs, exceptions, etc... And unlike tokens that are meaningless and expire, textual passwords last forever and are extensively re-used by user across websites.