Authenticating REST requests from a headless front end

carlos carlos 1 month ago

We're building a headless front end and calling jetonomy/v1 directly. What's the recommended auth approach — application passwords, nonces, or something else for server-to-server calls?

11

Solid breakdown. The only thing I would add is to back up before making the change — better safe than sorry.

Adding a small note: the same idea applies on mobile, just with a bit more attention to tap targets.

This deserves more votes. It is a small change with an outsized impact on day-to-day use.

Thanks for writing this up. Bookmarking it — the kind of thing I will want to reference again in a month.

Following this thread closely. We are about to face the exact same decision and the replies here are gold.

Click Any Link Below To Find Out More

This will close in 0 seconds