Concepts / Authentication and Authorization Basics

Authentication and Authorization Basics

API keys are the mechanism vendors use to identify users and monitor their service consumption.

  • Programming

The Missing Identity

When your application sends a request to a vendor's API, the vendor needs to know who is making the call. Without identification, the vendor cannot distinguish one user from another. That makes it impossible to track who is consuming the service or enforce usage policies. An API key supplies the connection between a request and the account that made it.

What do you think happens?

What information does a vendor lack when an API request arrives without an API key?

  • Which user account made the request
  • Which user account made the request and how much service that account has consumed
  • Only the name of the application
Reveal answer

Answer: Which user account made the request and how much service that account has consumed

The vendor uses the API key to identify the user, monitor service consumption, and enforce policies about usage.

From Request to User Account

An API key is a unique identifier included with an API request. Each key is associated with a user account. When the vendor's server receives the request, it extracts the key, looks it up in its database of valid keys, and validates it. If the key is found and valid, the server retrieves the associated user account information. The request is now connected to a known user.

sends requestlooks up keyfinds valid associationClient requestAPI key includedVendor serverExtracts the keyKey databaseValid key lookupUser accountAssociated account
How does an API key move from a user's request to a vendor's system, and how does the vendor use it to identify that user?
  1. The client sends a request that includes an API key.
  2. The vendor's server extracts the key from the request.
  3. The server looks up the key in its database of valid keys.
  4. The server retrieves the associated user account when the key is valid.
  5. The vendor can process the request with knowledge of who is making the call.

Counting and Controlling Usage

Identification is useful because it gives the vendor a basis for managing consumption. After the request has been processed, the vendor increments the usage counter for the identified account. The vendor can therefore monitor how much service each user is consuming, track usage for billing, and enforce rate limits.

validated keyaccount selectedusage checkedwithin policyover limitAPI requestAPI key includedUser accountIdentified by keyUsage counterAnother request recordedRate limitUsage policy checkedAllowed requestService continuesBlocked requestLimit exceeded
What happens after a vendor identifies a user: how is API usage counted and how does the system decide whether to allow or block another request?

The sequence matters: the vendor first connects the request to an account, then records that account's usage. Because the request is identified, the vendor can apply policies to the correct user rather than treating all requests as one undifferentiated stream.

Service Tiers and Access Decisions

The identified account also tells the vendor which service tier applies. A vendor might offer a free tier with limited requests per day and a premium tier with higher limits. By associating the API key with the account, the vendor can determine whether a request fits that account's usage policy and can manage access to the appropriate service tier.

has tierhas tierlimited policyhigher-limit policyrequest allowedUser accountFound through API keyFree tierLimited requestsUsage policyRequest evaluatedAPI serviceRequest handled under tierPremium tierHigher limits
How does the identified user's service tier affect request limits, available features, or access decisions?
QuestionIdentificationPolicy and authorization
What does the vendor determine?Which user account is making the callWhat usage rules or service tier apply
What supports the decision?A valid API key associated with an accountThe account's limits, tier, and tracked usage
Why is it needed?To connect activity to the correct userTo enforce limits and manage service access

Separate Keys for Separate Applications

Tracing usage by application

A single user has one web application, one mobile application, and one data analysis script. Each application uses a different API key. How can the vendor tell which application is consuming the most resources?

Connect each key: Each API key is associated with the same user account, but the keys are tracked independently.

Record requests separately: Requests from the web application, mobile application, and data analysis script are attributed to their respective keys.

Compare the tracked totals: The vendor can distinguish the consumption of each application instead of seeing only one combined total.

Use the detail: The user can see which application consumes the most resources and can optimize accordingly. A key can also be revoked without affecting the other keys.

Independent keys provide granular monitoring of applications belonging to the same user account.

ApplicationRequestsTracking result
Web application1,250Tracked through its own API key
Mobile application3,840Tracked through its own API key

The vendor can identify which application generated the requests because each application uses a different independently tracked key.

Mistakes Beginners Make

  • Treating an API request as identifiable without an API key

    Without identification, the vendor cannot distinguish one user from another or track whose account consumed the service.

    Fix: Include the API key with requests so the vendor can look up the associated user account.

  • Thinking an API key is used only to identify a user

    Vendors also use API keys to monitor consumption, enforce rate limits, manage service tiers, and track usage for billing.

    Fix: Treat identification as the first step in a larger usage-management process.

  • Combining every application under one indistinguishable tracking identity

    The vendor cannot independently track which application is consuming resources if the applications do not use separate keys.

    Fix: Use separate API keys when independent application-level tracking is useful.

  • Ignoring rate limits when designing an API client

    Service tiers can have different request limits, and an application may exceed the applicable limit.

    Fix: Plan for rate limits and implement error handling for cases in which the limit is exceeded.

Design Notes for API Clients

When designing an application that uses a vendor API, plan for how you will obtain, store, and use the API key. Also anticipate rate limits and implement error handling for cases in which the application exceeds them. These decisions connect the application's request behavior to the vendor's identification and usage-management process.

  • Know which account the API key represents.
  • Understand that the vendor validates the key on each request.
  • Expect usage to be monitored after the account is identified.
  • Account for the limits associated with the applicable service tier.
  • Use separate keys when independent application tracking is useful.
  • Plan error handling for requests that exceed a rate limit.

Check Your Understanding

MEDIUM

A user has a free-tier account and two applications. The user gives each application its own API key. Explain the sequence that allows the vendor to identify each application, track its requests, and apply the user's service-tier limits.

Hints
  • Start with what the client includes in each request.
  • Explain how the vendor connects each key to the user account.
  • Mention independent tracking for the two applications.
  • Finish by explaining how the account's service tier affects usage decisions.

Key Takeaways

  1. An API key connects an API request to the user account associated with that key.
  2. The vendor validates the key on each request and uses it to identify the caller.
  3. Once the caller is identified, the vendor can monitor usage, enforce rate limits, and track usage for billing.
  4. The associated account tells the vendor which service tier and usage policies apply.
  5. One user can own multiple independently tracked keys for different applications.

Key Takeaways

  • API keys solve the vendor's need to identify who is making an API request.
  • A valid key is looked up and connected to an associated user account.
  • That identity enables usage monitoring, rate limiting, service-tier management, and billing tracking.
  • Separate keys let one user monitor different applications independently.
  • API clients should anticipate rate limits and handle cases in which usage limits are exceeded.