2 ms·
This was helpful. I've looked at AWS before briefly, but this helped me understand the process better. This seems like a good set up for server to server API r
by turtle4 15y ago
This was helpful. I've looked at AWS before briefly, but this helped me understand the process better.
This seems like a good set up for server to server API requests. One question I still have is how to most safely query such an api from a client, rather than another server. ie, if my web app clients need to pull data from the rest api, is the only option to have them go through my web app server as a proxy, rather than pull the data from the rest api directly? I don't see a way around that.
- rkalla 15y agoturtle, I'm glad it helped... the whole subject had me confused until I looked into it more. If you need a client to communicate with the API, the client will need the private API key to encrypt the payload and then it can talk with the API directly. In AWS terms, this is the "Secret Key" that is hidden by default under your Account Access Security page. If you are trying to publish a public API though, for use by anyone and not "developers", you probably want to go with an OAuth approach. If you are controlling who has access by way of an API key though, going the route outlined in the article should be fine as every account would get a public/private key assigned to them.