Authentication Security Best Practices
api-keys-in-cookie
general > api-keys-in-cookie
Guidance
Your API accepts API keys that are transported in a header over the network. Because the credentials are sent over
the network on each API call, they are repeatedly exposed to unauthorized attempts to retrieve them.
Message
API keys should not be transported in cookies.
Examples
valid
components:
securitySchemes:
api_key:
type: apiKey
name: X-API-KEY
in: header
invalid
components:
securitySchemes:
api_key:
type: apiKey
name: X-API-KEY
in: cookie
Applies to SecurityScheme