Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

OAuth is perfectly valid as a standard for inter-API authentication but it is complicated. You'll also have to figure out separately how your oAuth clients manage the secrets they use to authenticate to the oAuth server to retrieve access tokens, and if encryption as well as authentication between the APIs is important to you, how to manage the keys to do so.

Take a look at https://spiffe.io/ which avoids these concerns focuses specifically for system to system authentication at scale.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: