API Authentication and Security Flashcards
6 cards from real API practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 API Authentication and Security flashcards as text
What does JWT stand for?
Answer: JSON Web Token
JWT stands for JSON Web Token, a compact, URL-safe token format used for securely transmitting information between parties.
Which part of a JWT contains the claims about the entity?
Answer: Payload
The payload section of a JWT contains the claims, which are statements about the entity (typically the user) and additional metadata.
What is OAuth 2.0 primarily used for?
Answer: Delegated authorization to APIs
OAuth 2.0 is an authorization framework that enables applications to obtain limited access to user accounts on third-party services.
Which HTTP header is used to send a Bearer token in API requests?
Answer: Authorization
Bearer tokens are sent in the Authorization header using the format 'Authorization: Bearer '.
What is an API key?
Answer: A unique identifier passed with requests to authenticate the client
An API key is a unique identifier passed in requests to authenticate the calling application or user.
Which attack involves injecting malicious scripts through API inputs that are reflected in responses?
Answer: Cross-Site Scripting (XSS)
Cross-Site Scripting (XSS) injects malicious scripts through API inputs that are reflected in web responses and executed in browsers.