I am developing an API that will be used by users of my customers. Here is what the flow will look like:

  1. User of my cloud based service creates an API key.
  2. User embeds the API key into their own custom applications.
  3. User deploys the application to their own end users.
  4. The application talks to our API.

I am looking for advice on how to secure this API. I see a few issues:

  1. API key has to be embedded into the users application and is therefore vulnerable to being stolen and abused.
  2. Once an API key is compromised, it can easily be disabled, but how will my users update their applications to use a new API key short of having to rebuild the application and redeploy.

Does anyone have any ideas on how to design this?

Edit
Report