3 ms·
Hmm.. you're right that it might introduce uncertainty about key formats, allowed chars/length etc. I'd like to avoid JWTs and use the simplicity of "Basic" (u
by dyml 6y ago
Hmm.. you're right that it might introduce uncertainty about key formats, allowed chars/length etc.
I'd like to avoid JWTs and use the simplicity of "Basic" (username/password)... but borrowing your idea I could generate it clientside on the website?
Enter email and immediately display a API key (base64 of email+random secret/guid) that is stored ("activated") when the first API call hits the server.
If you try to call the API with same email but different secret, it's 401.
It's indeed going to have a free tier with throttling. A paid tier with other rate limits and some premium features might come down the road.