How do I secure an ASP.NET core 6 web API for use by external clients?

Viewed 202

Currently we have an ASP.NET core 6.0 API hosted in Azure, based on the documentation on azure API management services security, it recommends using a subscription key to secure the API. It also recommends using Azure AD B2C, however it would be impossible to implement that on every client side application since some already run on other authentication frameworks.

Will subscription keys suffice as a secure way of accessing the API or is there another viable way?

Documentation: https://docs.microsoft.com/en-us/azure/active-directory-b2c/secure-api-management?tabs=app-reg-ga

1 Answers

This topic is covered perfectly regarding current best practices in the official ASP.NET Core documentation of Microsoft. You might be especially interested in the "Bearer Token Authentication" method: Authenticate with bearer tokens

Related