3 ms·
You need to assign the API key to an email both for contacting and also a way to limit abuse.
by resonantjacket5 5y ago
You need to assign the API key to an email both for contacting and also a way to limit abuse.
- KeepFlying 5y agoBut you could give a short lived highly limited API key out for testing to allow the potential user to test the API for their needs before bothering to make an account and providing their personal information.
- mcint 5y agoAlso, a way to register via that temporary api access
- 256DEV 5y agoKeepFlying's idea together with this point is a great suggestion, I'm going to see if I can prototype something along these lines. Basically hand out tons of short lived credentials right from a widget on the main landing page, together with each API response giving a link to a signup form that can convert the key into a fully fledged account. Thanks for the suggestion!
- stickfigure 5y agoHow do you prevent someone from automating repeated "get new temp key"?
- deleted 5y ago[deleted]
- 256DEV 5y agoAbuse of free APIs is a big issue, I've definitely experienced it a lot and see other API developers in this thread mentioning it. With my experience though I found that trying to limit signups to prevent abuse caused so much friction for legitimate users that I actually decide to change my strategy to the following: 1. Allow essentially unrestricted access to the free account on a separate domain/hosting so that people don't feel the need to churn through accounts with bots etc. and the load can be separated out. Hence this page: https://www.exchangerate-api.com/docs/free https://www.exchangerate-api.com/docs/free My signup form actually automatically redirects some classes of disposable email, bot signup etc. to this page! 2. Make sure that anything particularly resource intensive or that's a good reason to sign up for my service is only accessible after payment. I would love to give out more functionality for free but unfortunately the people that take advantage mean it's just not economically possible. So for me the main reason to get an email address is 1.) so that users can have a better experience - get usage notifications, updates about the API that might affect them, share the account with a colleague etc. And 2.) so that business users can be satisfied. Pretty much anyone running a company that is relying on an API will want to have an account, see how the upgrade process would work if they needed it etc. even if they're only starting off with a free plan.