SSH Key Based API Authentication
blog.the-space.agency
blog.the-space.agency
No. In fact, for API authentication, you want generally the least amount of cryptography you can get away with. A 128-bit random token, if you can. An HMAC'd token if you can't; if that's not enough, and you absolutely have to, a symmetrically-encrypted token. Asymmetric cryptography in an API design is usually a design smell, and a weakness.
This design, in particular, seems like a very bad idea. The reuse of any cryptography key in a new, different context should always make you break out in hives.
I’m sure the OP and plenty of others would appreciate it.
If you talk to public APIs, you're probably at some point encountering OAuth. It's not an accident that OAuth 2 has gotten rid of crypto and instead leaves it to the transport (HTTPS), where people are familiar with its use, nearly always have libraries etc available that handle it correctly for them, and upgrades on that layer, e.g. to new TLS versions, do not require OAuth 2 to change.
I'm not going to comment on whether this is a _good idea_. It is a clever way to leverage tools already available in dev environments to deploy API keys with encryption and hooked into your OS keyring (via the ssh-agent).
[0]: https://github.com/joyent/node-http-signature/blob/master/ht...
[1]: https://datatracker.ietf.org/doc/draft-cavage-http-signature...