HNHacker News
TopNewBestAskShowJobs

devCreek

0 karma · joined November 30, 2022

submissionscomments
devCreek··on API Key Authentication Best Practices
Regarding retrievable vs. irretrievable, I think is a matter of who do you delegate the ownership of the security. Using Irretrievable, you are transferring that to your users, which in a lot of scenarios just store them in plain text in non secure places.

I think having the chance to retrieve the api keys gives a much better Developer Experience to your consumers.