logoalt Hacker News

ttulyesterday at 2:53 PM3 repliesview on HN

Yet another argument for the death of the API key. Replacements abound; let's get on with it.


Replies

eddythompson80yesterday at 5:43 PM

API Keys will never die. Every time you would think you have killed them, some startup is gonna come and say "look how complicated it's to setup an OAuth flow just to get X from the other companies. Here is our setup" and it's 1 line of javascript or python with `let client = awesomeClient("{api-key}");` and everyone will love it.

LelouBilyesterday at 2:54 PM

Do you have any examples ?

It's the first time I hear about replacing API keys

show 4 replies
parliament32yesterday at 4:47 PM

And passwords. Shared secrets in general are a bad idea. If you're copy/pasting strings around to be used for authentication, you've done something wrong.

Workload identities and passwordless auth are the one true path.