3 ms·
He talks about wanting to charge for the API. If the javascript on your public website directly calls your (otherwise paid) API, how can you avoid exposing the
by bobbyi 15y ago
He talks about wanting to charge for the API. If the javascript on your public website directly calls your (otherwise paid) API, how can you avoid exposing the credentials it uses which are unmetered?
- Vandy_Travis 15y agoYou could make sure that the requesting page is on your domain.
- jonprins 15y agoIt's trivial to use a proxy to modify the referral headers.
- ceol 15y agoI recall some functionality in a PHP framework I was using that allowed you to make API calls on the server side through use of a class or function. It was something like $user = $api->GET('/accounts/the_user'); which would process the API call without actually making a separate HTTP request. Would this accomplish it?
- k7n4n5t3w4rt 15y agoMake the calls to the API over HTTPS.