Prompt
Need help picking API security for public endpoints and partner APIs
Latest observation
Sep 29, 2026
OpenAI APIWeb search: off
For public endpoints and partner APIs, the usual best choice is layered API security, not a single control.
Recommended approach
1) Public endpoints
Use:
- TLS everywhere
- OAuth 2.0 / OpenID Connect for user-facing APIs
- API keys only for identification, not as sole auth
- Rate limiting + throttling
- WAF / bot protection
- Input validation
- JWT access tokens with short lifetimes
- CORS only if browser clients need it
If the endpoint is truly public and does not require user identity, then use:
- anonymous access
- rate limiting
- abuse detection
- captcha or challenge flows for sensitive actions
2) Partner APIs
Use stronger trust controls:
- OAuth 2.0 client credentials for machine-to-machine access
- mTLS if partners are high trust or regulated
- Signed requests if you need non-repudiation or replay protection
- IP allowlisting as an extra layer, not the only control
- Per-partner scopes and quotas
- Dedicated API gateway policies
- Separate credentials per partner and per environment
A practical default
If you want a solid baseline:
- Public API: OAuth2/OIDC + JWT + rate limits + WAF
- Partner API: OAuth2 client credentials + scopes + mTLS for sensitive partners
- Admin/internal APIs: mTLS + RBAC + network restrictions
What not to rely on alone
- API keys alone
- IP allowlists alone
- Basic auth
- JWT without revocation/expiry strategy
- One shared credential across all partners
Simple decision guide
- Is there a user logging in? → OAuth2/OIDC
- Is it machine-to-machine partner access? → OAuth2 client credentials, optionally mTLS
- Need highest assurance? → mTLS + OAuth2 + signed requests
- Need only public read access? → anonymous + throttling + WAF
If you want, I can give you:
- a recommended security architecture for your exact setup, or
- a comparison table of OAuth, API keys, mTLS, and signed requests.