Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I failed to find much concrete around how to use OAuth to protect an API, and no code samples.

I think this may have been an oversight during the final editing process. I ended up having to split this up into two articles, as you surmised.

The second one is a blow by blow of the authorization code grant (and how an API should validate a token) and will be published later this week.

But I should have caught that we promised the code in the intro and removed that.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: