Currently we have an ASP.NET core 6.0 API hosted in Azure, based on the documentation on azure API management services security, it recommends using a subscription key to secure the API. It also recommends using Azure AD B2C, however it would be impossible to implement that on every client side application since some already run on other authentication frameworks.
Will subscription keys suffice as a secure way of accessing the API or is there another viable way?
Documentation: https://docs.microsoft.com/en-us/azure/active-directory-b2c/secure-api-management?tabs=app-reg-ga