Skip to Content
Designing APIs with Swagger and OpenAPI
book

Designing APIs with Swagger and OpenAPI

by Lukas Rosenstock, Joshua Ponelat
June 2022
Intermediate to advanced
424 pages
11h 50m
English
Manning Publications
Content preview from Designing APIs with Swagger and OpenAPI

7 Adding authentication and authorization

This chapter covers

  • Identifying the difference between authentication and authorization
  • Adding operations for creating users
  • Adding an operation for getting a user’s token (authentication)
  • Adding the Authorization header to the POST /reviews operation (authorization)

We’re going to look at authentication and authorization in this chapter (see figure 7.1), two close friends in APIs that are often a little misunderstood. Authentication is about proving you are who you say you are, which could be done with a username and password. Authorization is about being allowed access to particular actions or resources, such as getting user details or creating a new review.

Figure 7.1 Where we are

APIs almost always ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Design and Build Great Web APIs

Design and Build Great Web APIs

Mike Amundsen
Mastering API Architecture

Mastering API Architecture

James Gough, Daniel Bryant, Matthew Auburn

Publisher Resources

ISBN: 9781617296284Supplemental ContentPublisher SupportOtherPublisher WebsiteSupplemental ContentErrata PagePurchase Link