🛂Authentication
The SIGNIUS portal supports two authentication methods – API Key Authentication and mutual TLS Authentication
API Key authentication
The API key string is a random string of considerable length, for example:
X-Api-Key: 3H06Ydk2Al4aSBuT6zXAuXEqOI6VdSxZyADZshuvmvcTqr60WQBAob78Lpkjh7Le
.
When you use an API key to authenticate, you always pass the key’s string as a X-Api-Key header sent to the SIGNIUS API, which is later used to authorize the user executing action. In regards of security the key string should be considered a password.
Mutual Certificate authentication
To ensure maximum communication security SIGNIUS API allows the use of certificate authentication process. In this solution the certificate public keys have to be exchanged first, before the communication process occurs (see Getting Started).
Afterwards during standard communication each time a request is sent to the Signius API first a mTLS connection has to be estabilished. In the process each of the sides (Client and Server) trust each other based on previously exchanged certificates.
Last updated