Why do web APIs tend to use pre-shared keys for client auth instead of pubkeys?crypto.stackexchange.com 2zhxshen4y1 comment