Secure Vercel Serverless Function

Viewed 294

I am currently building on Vercel an use the serverless functions as an API. All functions are available in <URL>/api/<FUNCTION_NAME>. I want to only allow my web page the access to the API but I have no idea how. I don't have any Authentication / JWT system in place because it is a fairly simple app. In AWS I normally use something like IAM authentication or a simple API Key.

What are best practices for that or what is the suggested way to do this? I am not sure if I look at the problem completely wrong but I don't find many resources for that.

Thanks! Sandro

1 Answers

As mentioned in here, you actually can use a simple method using QUERY. For example you can run a function to authorize it if QUERY.SECRET_KEY is equal to the secret key that you saved somewhere else on your code eg. env variable. Or using the same method, you can now use the authorization header that is sent by client. Here the example. You can use anything that suits you. It's just about personal preference. Hope it helps.

Related