There is more of this guide.
Practice
4 questions- API designDesign API-key management for a public API: issuance, scoping, rotation, and revocation. What makes rotation something customers actually do instead of fear?
- API designDesign the API for a multi-tenant SaaS application where each tenant has isolated data. How do you model tenant context in requests, and what safeguards prevent cross-tenant data leakage?
- API designDesign the authentication flow for a public API offering both API keys and OAuth 2.0. When would you recommend each, and how do you communicate which scopes or permissions are missing?
- API designYour API uses OAuth 2.0 with refresh tokens. A client's refresh token is about to expire. How do you communicate this in advance, and what's your rotation strategy?