4 ms·
Here are a few of the articles I've found: http://www.thebuzzmedia.com/designing-a-secure-rest-api-without-oauth-authentication/ http://www.thebuzzmedia.com/de
by colevscode 15y ago
Here are a few of the articles I've found:
http://www.thebuzzmedia.com/designing-a-secure-rest-api-without-oauth-authentication/ http://www.thebuzzmedia.com/designing-a-secure-rest-api-with...
Complete, easy to understand article that outlines the HMAC approach but suggests that things can be much simpler if HTTPS is employed.
http://broadcast.oreilly.com/2009/12/principles-for-standardized-rest-authentication.html http://broadcast.oreilly.com/2009/12/principles-for-standard...
Claims that you should use HTTPS and sign your queries using a private key. This seems onerous for the API user.