Have you considered 2 factor authentication? If you are concerned about security 2FA can give you more protection-
-
Maruf
That sounds interesting, how would you implement that on an API level in a good way? I mean, the clients applications will most probably do automatic transactions all the time.
Are you thinking something like time-based sessions, which you have to authenticate on both ends - with a PK?
But Yes, I have to admit, for API, this may be overkill-
I also think this might be a bit overkill - maybe something for real enterprise apps... :-)
But it's a cool thought!
Thanks for sharing!