I'm designing a REST api that allow client side to POST (create) a resource.
Let's call my resource is Subscription and my REST api accepts a Dto called Subscription
The POST request needs to be sent together with a captcha token that will be verified on server side.
My question is where would be the best place to put the captcha token, there're some options that I'm thinking about:
- Directly inside
Subscription - As a parameter in URL, e.g: /subscriptions?captcha_token=abcd1234
- As a HTTP header
- Create a new Dto that wraps
Subscriptionand carry fieldcaptchaToken
Any other suggestion are welcome.
Thank you.