API authentication

API authentication establishes which client is calling. Between machines there is nobody present to be phished, and nobody present to notice anything wrong either.

That changes the failure modes. There is no user to spot a strange prompt, no second factor, and credentials that live in configuration for years. Machine-to-machine authentication needs short-lived, verifiable identity precisely because the human safeguards that partially compensate elsewhere do not exist.

Checked against the primary source.

More on API security