Chapter 7. Secure Access Tokens
Access tokens are essentially text strings that serve as message credentials. In some ways, access tokens are similar to API keys but access tokens are much more versatile, offering features such as expiration, limited scope of access, or revocation. They enable an end-to-end security solution that meets the main security requirements of both APIs and clients.
In our experience, developers and architects do not often fully understand the best practices for using access tokens securely. Therefore, in this chapter, we provide an end-to-end set of security requirements for your access tokens that considers both APIs and clients. We explain the different token formats you can use so that clients receive access tokens that do not reveal sensitive data, while APIs receive access tokens that enable them to authorize requests correctly. We then describe how to deliver access tokens from clients to APIs and translate between token formats. Finally, we explain the options you have for increasing the security strength of access tokens and reducing the impact of any token breaches. We show that, with the right separation, you can use the most secure options without adversely affecting either APIs or clients.
Let’s get started by providing a list of the main requirements for secure access tokens.
Secure Access Token Requirements
Access tokens play a vital role in the security of your APIs. The main role of access tokens is to provide your APIs with the data ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access