Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's the bearer token authorization method. Pretty standard nowadays for many APIs.

https://swagger.io/docs/specification/authentication/bearer-...



API keys have been around for a long time without needing the prefix. I could understand the Bearer prefix when using JWT-style tokens. I could also see using it if there were indeed an Oauth flow involved. But in this case just seems like a nuisance.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: