API Authentication¶
Overview¶
This document describes authentication methods for BrainSAIT APIs.
Authentication Methods¶
API Key¶
OAuth 2.0¶
POST /oauth/token
Content-Type: application/x-www-form-urlencoded
grant_type=client_credentials
&client_id=your-client-id
&client_secret=your-secret
Response:
Usage:
Security Best Practices¶
- Never expose secrets in client-side code
- Rotate keys regularly
- Use HTTPS always
- Limit scopes to minimum needed
- Monitor usage for anomalies
Key Management¶
- Generate keys in dashboard
- Revoke compromised keys immediately
- Use different keys per environment
Related Documents¶
Last updated: January 2025