api-authentication

Implement secure API authentication with JWT, OAuth 2.0, API keys, and session management. Use when securing APIs, managing tokens, or implementing user authentication flows.

By aj-geddes · 584 installs

npx skills add aj-geddes/useful-ai-prompts --skill api-authentication

Source repository · Upstream listing

API Authentication Table of Contents [Overview]( overview) [When to Use]( when to use) [Quick Start]( quick start) [Reference Guides]( reference guides) [Best Practices]( best practices) Overview Implement comprehensive authentication strategies for APIs including JWT tokens, OAuth 2.0, API keys, and session management with proper security practices. When to Use Securing API endpoints Implementing user login/logout flows Managing access tokens and refresh tokens Integrating OAuth 2.0 providers Protecting sensitive data Implementing API key authentication Quick Start Minimal working example: Reference Guides Detailed implementations in the references/ directory: Guide Contents [JWT Authentication](references/jwt authentication.md) JWT Authentication [OAuth 2.0 Implementation](references/oauth 20 implementation.md) OAuth 2.0 Implementation [API Key Authentication](references/api key authentication.md) API Key Authentication [Python Authentication Implementation](references/python authentication implementation.md) Python Authentication Implementation Best Practices ✅ DO Use HTTPS for all authentication Store tokens securely (HttpOnly cookies) Implement token refresh mechanism Set appropriate token expiration times Hash and salt passwords Use strong secret keys Validate tokens on every request Implement rate limiting on auth endpoints Log authentication attempts Rotate secrets regularly ❌ DON'T Store passwords in plain text Send tokens in URL parameters Use weak secret keys Store sensitive data in JWT payload Ignore token expiration Disable HTTPS in production Log sensitive tokens Reuse API keys across services Store credentials in code