Prompt
What are API authentication best practices?
Latest observation
Aug 27, 2026
OpenAI APIWeb search: off
Here are the main API authentication best practices:
-
Use strong, modern auth methods
- Prefer OAuth 2.0 / OpenID Connect for user-facing apps.
- Use short-lived access tokens and refresh tokens when appropriate.
- For service-to-service auth, use mTLS, signed JWTs, or client credentials.
-
Never send credentials in plaintext
- Always use HTTPS/TLS.
- Reject non-TLS traffic.
-
Use least privilege
- Give each client only the minimum scopes/permissions needed.
- Separate credentials by app, environment, and role.
-
Keep tokens short-lived
- Short expiration reduces damage if a token is stolen.
- Rotate refresh tokens and revoke them when suspicious activity is detected.
-
Store secrets securely
- Use a secret manager or vault, not source code or config files.
- Never hardcode API keys in frontend apps or public repos.
-
Rotate and revoke credentials
- Support key rotation without downtime.
- Provide a way to revoke compromised tokens/keys immediately.
-
Validate tokens properly
- Check signature, issuer, audience, expiration, and not-before claims.
- Do not accept unsigned or weakly signed tokens.
-
Protect against replay and abuse
- Use nonces, timestamps, or one-time tokens where needed.
- Rate limit authentication endpoints and sensitive APIs.
- Add anomaly detection for unusual login/API usage patterns.
-
Use secure session handling
- If using cookies, set HttpOnly, Secure, and SameSite.
- Prefer stateless tokens only when appropriate; avoid long-lived bearer tokens if possible.
-
Log carefully
- Log auth events, failures, and token issuance/rotation.
- Never log secrets, full tokens, passwords, or sensitive claims.
-
Support MFA for interactive users
- Especially for admin accounts and privileged actions.
-
Design for key separation
- Different keys for dev/staging/prod.
- Distinguish machine, user, and admin credentials.
-
Be cautious with API keys
- API keys identify the caller, but often do not provide strong authentication by themselves.
- Combine them with other controls if used at all.
-
Follow standards
- Use proven libraries and standards instead of custom cryptography or bespoke auth schemes.
If you want, I can also give you:
- a checklist for REST APIs
- best practices for JWT
- best practices for API keys vs OAuth
- a production security checklist for APIs
Brands