logoalt Hacker News

tptacektoday at 1:00 AM1 replyview on HN

https://fly.io/blog/api-tokens-a-tedious-survey/

tl;dr: most of the time you should use opaque random strings.


Replies

ForHackernewstoday at 8:49 AM

API tokens are a very small narrow part of the authorization universe. Having a shared secret relies on a trust relationship between the resource server and the identity provider that does not exist between, say, my SaaS backend and Google or Meta's login system.

show 1 reply