Authenticating REST requests from a headless front end

carlos carlos 1 month ago

We're building a headless front end and calling jetonomy/v1 directly. What's the recommended auth approach — application passwords, nonces, or something else for server-to-server calls?

7

Adding a small note: the same idea applies on mobile, just with a bit more attention to tap targets.

This deserves more votes. It is a small change with an outsized impact on day-to-day use.

Thanks for writing this up. Bookmarking it — the kind of thing I will want to reference again in a month.

Following this thread closely. We are about to face the exact same decision and the replies here are gold.

Solid breakdown. The only thing I would add is to back up before making the change — better safe than sorry.

Click Any Link Below To Find Out More

This will close in 0 seconds