Module
Module 4 of 6Lesson 1 of 2~18 min

API keys, tokens and OAuth 2.0, choosing and specifying

Lesson 1 of the module "Authentication, permissions and security" in the course "Design and test an API integration as a PM".

Lesson objective

By the end of this lesson, you will be able to choose the authentication method suited to an integration (API key, token, OAuth 2.0 and its flow), specify the minimal scopes and the connection journey, and write the rules for managing secrets.

Where it fits

Authentication, permissions and security

Who may call the API, to do what, and how do you avoid the most common flaws?

Lessons in this module

  1. API keys, tokens and OAuth 2.0, choosing and specifying (this lesson)
  2. The API flaws a PM should know how to spot

What you will learn in the course

This lesson is part of the course Design and test an API integration as a PM

  • Read a REST API's documentation (resources, endpoints, methods, parameters, JSON bodies, OpenAPI description) and extract what the integration needs.
  • Send, save and test requests in Postman or Bruno (collection, environments, variables, assertions) to check an API's real behavior.
  • Interpret status codes and error responses, and decide the product behavior (fix, retry, alert, inform the user).
  • Choose and specify the authentication method (API key, token, OAuth 2.0), the minimal permissions and the rules for managing secrets.
  • Specify pagination, rate-limit handling, webhooks and idempotency for an integration that withstands volumes, outages and duplicates.
  • Plan environments (sandbox, production), versions, breaking changes and deprecations in the spec and the test plan.
  • Write a complete integration spec, with a collection of tested requests, ready to be estimated by the team.