top of page

Welcome
to NumpyNinja Blogs

NumpyNinja: Blogs. Demystifying Tech,

One Blog at a Time.
Millions of views. 

API Authorization Methodologies

May 2, 2025
7 min read

Updated: May 26, 2025

We live in a world where APIs are an inevitable part of our daily life, whether it's the map app on your phone, social media or your trusty weather app, APIs are everywhere. So it's very important to understand what an API is, how it works and how to protect it from unauthorized access 


APIs (Application Programming Interface) are a set of rules and protocols that two software applications have to follow so that they can interact with each other. It defines the format in which requests and responses are sent, the structure of the data exchanged ect. Thus an application can interact with another without having to understand how it works internally.

Important concepts of an API are:

  1. EndPoints: An endpoint is a URL which is a uniform locator for a particular resource that you want to interact with on the server. Each endpoint provides a specific resource.

  2. Requests: When a client needs to access a particular resource, it sends an API request to the server’s endpoint. Each request includes one http method like GET, POST, PUT,PATCH,DELETE etc.

  3. Response: Once the server receives the request, the API sends a response back to the client usually in a JSON or XML format.

Example for a JSON response:

{

“First Name” : “John”,

“Last Name” : “Honai”,

“Email” : “johnhonai@gmail.com”

}

  1. API Authentication : API authentication and authorization make sure that the API can be accessed only by authorized users. 

API Security

APIs are meant to be interacted with programmatically and that's the whole reason we create them; it allows all sorts of powerful interactions between applications. But it makes them vulnerable too. One of the most common ways that attackers get into systems is through APIs. That’s why API security is the most important thing to consider when developing an application.Securing an API involves two things; authentication and authorization 


API Authentication and Authorization 

Authentication is about determining who you really are. It involves putting in a password or providing a key that proves that you are who you say you are. On the other hand, authorization is about making sure that you can only access the things you are allowed to access. Meaning, authorization determines which data you can see and interact with.

For example, imagine you are checking into a hotel room. You need to go to the front desk to check in. There the clerk verifies that you can have access to that specific room by checking your ID and swiping your credit card. If everything looks good, the clerk hands you the key to your room. This is the authentication part. Now that you have the key, you can access your room. But it doesn’t let you into other rooms in the hotel because you are authorized to access your room only. But the hotel has a master key that lets its staff, say the cleaning staff, enter all rooms of the hotel. The master key gives a higher level of authorization to the staff. Meaning authentication is about verifying the identity of the user while authorization is about verifying user roles.Both of these features are crucial to a properly working security system. 

Now let's look into some of the important API authorization methods. These are the most common ones:

  • Basic authentication

  • API keys

  • JSON web tokens(JWT)

  • OAuth((Open Authorization)


1. Basic Auth

Basic auth is one of the simpler authorization out there. This option is used for APIs that require a username and password in order to use it. These credentials are encoded using Base64 encoding and sent as a part of the request header. The value of the header starts with the keyword “Basic” and this is how the server knows that you are using basic authorization for the request.

This is how basic auth works:

  1. Client sends request to the server asking for a protected resource

  2. Server requests username and password to validate the client

  3. Client sends the credentials encoded in Base64 

  4. Server validates the username and password. If the user is authorized, the server returns requested resources. If the username or password is incorrect, a 401 Unauthorized code is returned



Example:

Auth string: admin:admin

Base64 encoded auth string: YWRtaW46YWRtaW4=

 Even though it is the simplest, it is not generally recommended or used in production because base64 is not secured. It's very easy to decode base64 and extract the username and password from the request. If you must use base auth anyway, make sure you are using a secure connection(https) to avoid man-in-the-middle attacks. Most of the APIs don't use basic auth, instead they rely on more complex authorization schemes.

2. API Keys

Imagine you have a VIP pass to an exclusive event. Everytime you show the pass, the security lets you in.This is basically how API keys work; it's a simple unique identifier that enables a client to access an API. This is the architecture of an API key:


When a client needs to access the API of the server, it registers at the server. The server sends an API key to the client. An API key is a long, randomly generated string of characters. Then the  client includes this key in the request. If the key is valid, the API allows the request to proceed; if it's invalid, a 401 Unauthorized code is returned. You can send the API key as a query parameter. But it is not recommended as the key might be exposed in the url. A more secure way is to send it as a part of the request header. This way, the key stays hidden from the url. Bearer token is an example of an API key. 




Example of an API key as a part of request header:

Authorization: Bearer 4e4d3f8e9a2f4bd0b4283e478f4c0fa1


API keys work best when you need basic authorization without user's specific data. This will be a good option when you are using public APIs like weather,maps,stock market data etc.

The best practices to follow while using API key:


  1. Keep the key secret to avoid unauthorized access

  2. Limit permissions(read only, write etc) to the client

  3. Limit the number of times a client can access the API at a given period of time to avoid overuse.

  4. Make sure the API is not being misused


3. JWT(Json Web Token)

Imagine you walk into an event with a special wristband. Instead of showing your id or ticket every time, you just have to show your wristband; it proves that you are allowed inside. JWT functions exactly like this. It is a widely used method to authenticate web and mobile apps allowing users to login once and remain authenticated without having to specify every time. So what exactly is JWT? JWT is widely used to securely transmit data between client and server in the form of JSON objects. 


This is the architecture of JWT:


  1. The user logs to the server using the user id and password

  2. Server validates the credentials and generates a JWT key and signs it using a secret key. And then the key is sent to the client

  3. The client saves the key locally. When it is time to send a request to the server, it attaches the JWT as a part of the request header.

  4. Server checks if the token is valid and hasn’t expired. If everything looks good, the request is processed   





Unlike API keys which are static keys, JWTs contain structured information that can be verified and structured. A JWT has three parts separated by “.” . The first part is the header which specifies the type of token and the algorithm used for encryption. Payload contains the actual data and Signature ensures the token is authentic and hasn’t been tampered  with.

Example of JWT:

eyJhbGciOiAiSFMyNTYiLCJ0eXAiOiAiSldUIn0.eyJzdWIiOiAiMTIzNDU2Nzg5MCIsIm5hbWUiOiAiSm9obiBEb2UiLCJpYXQiOiAxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

  •  Header (Base64Url encoded): {"alg": "HS256", "typ": "JWT"}

      Encoded: eyJhbGciOiAiSFMyNTYiLCJ0eXAiOiAiSldUIn0

  • Payload (Base64Url encoded) :{"sub": "1234567890", "name": "John Doe", "iat": 1516239022}    Encoded:eyJzdWIiOiAiMTIzNDU2Nzg5MCIsIm5hbWUiOiAiSm9obiBEb2UiLCJpYXQiOiAxNTE2MjM5MDIyfQ

  • Signature (Base64Url encoded):A signature based on the header, payload, and a secret key.

        Example: SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Because the JWT is signed by a secret key, it can be verified without storing the client session data in the server. This makes JWT stateless and scalable and it is the best option to use in applications where authentication has to be fast and scalable 



4. OAuth(Open Authorization)

OAuth is the most popular authorization protocol commonly used to grant third party applications limited access to user data from other services like social media platforms or cloud storage without exposing user credentials with the third party. Sounds confusing? Let me explain with an example:

OAuth works through a series of steps to grant access. Imagine you are signing up for a new app. Instead of creating a new account, you can login with google. These are are the steps involved in the process:


1. Redirecting to authorization server : You are redirected to google where you see a prompt   

    asking if you grant this app access to your google account.

2. User grants permission: You approve the request and log in. Google generates an

    authorization code and sends it back to the app.

3. App exchanges code for a token: App sends this code to google’s authorization server which

    then provides an access token. 

4. Server grants access: This token allows the app to fetch your data securelyAccessing

    resources: Whenever the app needs to access your data, it uses the access token instead of 

    storing your password




OAuth 2.0 is the widely used version of OAuth . It is designed to be used across web, mobile and API based applications, making it one of the most powerful authorization methods today. APIs like Github and twitter use OAuth to let third party apps interact with them securely like scheduling tweets or accessing their repository.

Conclusion

We have seen what APIs are and what they do. SInce they are exposed over the internet, they are vulnerable to attacks. We use different authorization methods to protect APIs from such attacks. So which authorization is right for you? It depends on your use case. API keys are best for simple server to server communication. It is a quick way to authorize a request. JWT is great for stateless authorization for web and mobile apps. If you need a secure scalable way to manage user sessions without storing credentials on the server, JWT is a strong choice. OAuth is perfect when users need to authorize a third party service like google or facebook. If your app requires delegated permissions and access to external APIs, OAuth is the way to go.




 
 

+1 (302) 200-8320

NumPy_Ninja_Logo (1).png

Numpy Ninja Inc. 8 The Grn Ste A Dover, DE 19901

© Copyright 2025 by Numpy Ninja Inc.

  • Twitter
  • LinkedIn
bottom of page