Description
Requiring API key authentication in an individual operation’s security is valid. Calling that operation over unencrypted HTTP can expose the key in transit, so HTTPS is necessary.
Potential impact
Someone who obtains an exposed key may perform the API operations permitted by that key.
Remediation
Require HTTPS in the server and clients for that operation, and send the key in a header instead of the URL. Align the documented and actual authentication policies, keep keys out of logs, and revoke and replace exposed keys.
Examples
These OpenAPI 3.0 excerpts use HTTPS for the API server URL of the /pets operation and show switching to OAuth2 as an option. OAuth2 alone does not encrypt API traffic. Retaining API keys with HTTPS and headers is also valid; apply the settings to the actual server and clients.
Before
{
"openapi": "3.0.0",
"servers": [{"url": "http://api.example.com"}],
"paths": {
"/pets": {
"post": {
"security": [
{
"apiKeyAuth": []
}
]
}
}
},
"components": {
"securitySchemes": {
"apiKeyAuth": {
"type": "apiKey",
"name": "X-API-Key",
"in": "query"
}
}
}
}
After
{
"openapi": "3.0.0",
"servers": [{"url": "https://api.example.com"}],
"paths": {
"/pets": {
"post": {
"security": [
{
"OAuth2": [
"write",
"read"
]
}
]
}
}
},
"components": {
"securitySchemes": {
"OAuth2": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://example.com/oauth/authorize",
"tokenUrl": "https://example.com/oauth/token",
"scopes": {
"write": "modify objects in your account",
"read": "read objects in your account"
}
}
}
}
}
}
}