If a person wants to use our API , he does the following:
- Receives a token
- With token accesses
API
Naturally, the tokens will be unique.
Actually, the question is: How to protect this token? That it was available only for one person. That is, that it was impossible to take this token from another person and set yourself. What do you need to tie?
IPis not suitable, as it can be dynamic.Referer- also not suitable, because you can replace
There should also be a "cross-platform" token, that is, to take it, and, for example, transfer it to an Android application and use the API
PS Need without user registration (!)
Any ideas?