Skip to content

Comment on Secure Your REST APIparent

Comments

> At the same time, API credentials should by definition be single-use.

Could you spell this one out a little bit more? Do you mean only a single session should be able to use an API credential?

I mean the credential should only be relevant to the service, never shared across multiple services, because the API generates it for you.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.