← Back to problems

64. Scoped API Key Provisioning Service

MEDIUM
AuthenticationDatabaseSecuritySystem Design

Design the API and schema for issuing, scoping, and revoking programmatic access keys - never returning the raw secret twice.

Design a service for issuing programmatic API keys (modeled on cloud platforms' access-key systems): a user can generate a scoped key, list their keys, and revoke one. The raw secret is shown exactly once at creation and never again. Design the REST endpoints and the schema for storing keys, deliberately without an infrastructure diagram.
Log in to submit a solution

Comments

Log into join the discussion.