{
    "api": "YAML JSON TOON Database",
    "version": "1.0.0",
    "format": "json",
    "dataset": {
        "id": 56,
        "slug": "http-authentication-methods",
        "title": "HTTP Authentication Methods",
        "description": "HTTP authentication schemes: Basic, Bearer (JWT), Digest, OAuth 2.0, Mutual TLS, and modern alternatives like WebAuthn and passkeys.",
        "summary": "HTTP authentication schemes compared with their RFC, header, security level, typical uses and notes, from Basic and Bearer tokens to OAuth 2.0, OpenID Connect, mutual TLS, API keys and WebAuthn passkeys, followed by a short list of best practices.",
        "use_when": [
            "You are choosing an authentication scheme for an API or web application.",
            "You need the header format and security properties of each."
        ],
        "caveats": [
            "A scheme is only as strong as its deployment: HTTPS is required for Basic and Bearer, and tokens must be stored, scoped and revoked properly.",
            "OAuth 2.0 is an authorization framework; authentication needs OpenID Connect or another layer."
        ],
        "related": [
            "authentication-factors",
            "http-client-error-guide",
            "http-request-headers",
            "common-vulnerabilities-owasp"
        ],
        "category": "HTTP Status Codes",
        "category_slug": "http-status-codes",
        "tags": "http,authentication,basic,bearer,jwt,oauth2,digest,webauthn,passkeys",
        "view_count": 0,
        "created_at": 1778695229,
        "updated_at": 1778695229,
        "entry_count": 16,
        "fields": [
            {
                "section": "schemes",
                "field": "name",
                "type": "string",
                "example": "Basic Authentication"
            },
            {
                "section": "schemes",
                "field": "rfc",
                "type": "string",
                "example": "RFC 7617"
            },
            {
                "section": "schemes",
                "field": "header",
                "type": "string",
                "example": "Authorization: Basic base64(username:password)"
            },
            {
                "section": "schemes",
                "field": "security",
                "type": "string",
                "example": "Low (credentials sent with every request, base6…"
            },
            {
                "section": "schemes",
                "field": "use_cases",
                "type": "array",
                "example": "[3 items]"
            },
            {
                "section": "schemes",
                "field": "notes",
                "type": "string",
                "example": "Always use HTTPS; consider rotating credentials…"
            },
            {
                "section": "best_practices",
                "field": "*",
                "type": "array",
                "example": "[8 items]"
            }
        ]
    },
    "data": {
        "schemes": [
            {
                "name": "Basic Authentication",
                "rfc": "RFC 7617",
                "header": "Authorization: Basic base64(username:password)",
                "security": "Low (credentials sent with every request, base64 is encoding not encryption)",
                "use_cases": [
                    "Simple internal tools",
                    "Development/testing",
                    "Service-to-service with HTTPS only"
                ],
                "notes": "Always use HTTPS; consider rotating credentials; prefer token-based auth for production"
            },
            {
                "name": "Bearer Token (JWT)",
                "rfc": "RFC 6750, RFC 7519",
                "header": "Authorization: Bearer <jwt_token>",
                "security": "Medium (stateless, self-contained, but token theft = full access)",
                "use_cases": [
                    "SPA + API",
                    "Mobile apps",
                    "Microservices",
                    "Third-party integrations"
                ],
                "notes": "Use short-lived access tokens (15min) + refresh tokens; store in httpOnly cookies for web; never in localStorage for XSS-prone apps"
            },
            {
                "name": "Digest Authentication",
                "rfc": "RFC 7616",
                "header": "Authorization: Digest username=\"user\", realm=\"...\", nonce=\"...\", uri=\"...\", response=\"...\"",
                "security": "Medium (password not sent in clear, but vulnerable to MITM without HTTPS)",
                "use_cases": [
                    "Legacy systems",
                    "WebDAV",
                    "IP cameras",
                    "Embedded devices"
                ],
                "notes": "Rarely used in modern web apps; OAuth 2.0 / JWT preferred"
            },
            {
                "name": "OAuth 2.0",
                "rfc": "RFC 6749, RFC 6750",
                "header": "Authorization: Bearer <access_token>",
                "security": "High (when implemented correctly with PKCE, short-lived tokens, secure storage)",
                "use_cases": [
                    "Third-party authorization",
                    "SSO",
                    "API delegation",
                    "Mobile/web app auth"
                ],
                "notes": "Use OAuth 2.1 (draft): enforces PKCE, removes implicit flow, requires refresh token rotation"
            },
            {
                "name": "OAuth 2.0 + OpenID Connect",
                "rfc": "OpenID Connect Core 1.0",
                "header": "Authorization: Bearer <id_token + access_token>",
                "security": "High (adds identity layer on top of OAuth 2.0)",
                "use_cases": [
                    "User authentication (not just authorization)",
                    "SSO across domains",
                    "Social login"
                ],
                "notes": "ID token (JWT) contains user identity claims; access token for API access"
            },
            {
                "name": "Mutual TLS (mTLS)",
                "rfc": "RFC 8705",
                "header": "Client certificate in TLS handshake",
                "security": "Very High (certificate-based,双向认证)",
                "use_cases": [
                    "Service-to-service (zero-trust)",
                    "High-security APIs",
                    "Financial APIs",
                    "B2B integrations"
                ],
                "notes": "Server validates client certificate; often combined with OAuth 2.0 (OAuth 2.0 mTLS sender-constrained tokens)"
            },
            {
                "name": "API Keys",
                "rfc": "N/A (convention)",
                "header": "X-API-Key: <key> OR Authorization: ApiKey <key>",
                "security": "Low-Medium (no standardization, key theft = full access, no expiry by default)",
                "use_cases": [
                    "Developer API access",
                    "Rate limiting by key",
                    "Simple service access",
                    "Analytics/tracking"
                ],
                "notes": "Not an authentication scheme per se; use for identification, not authentication; rotate keys; set expiry"
            },
            {
                "name": "WebAuthn / Passkeys",
                "rfc": "W3C WebAuthn Level 3, FIDO2",
                "header": "Public key credential assertion in JSON (not HTTP header based)",
                "security": "Very High (phishing-resistant, hardware-backed, no shared secrets)",
                "use_cases": [
                    "Passwordless login",
                    "MFA second factor",
                    "Mobile app authentication",
                    "Enterprise SSO"
                ],
                "notes": "Uses public key cryptography; server stores public key, client holds private key; supported by all major browsers"
            }
        ],
        "best_practices": [
            "Always use HTTPS (TLS 1.2+)",
            "Use short-lived access tokens (15-60 min) with refresh token rotation",
            "Store tokens in httpOnly, Secure, SameSite cookies for web apps (not localStorage)",
            "Implement token revocation (blacklist or short TTL)",
            "Use PKCE for public clients (SPAs, mobile apps)",
            "Validate token audience (aud claim) and issuer (iss claim)",
            "Implement rate limiting per authenticated identity",
            "Log authentication events for anomaly detection"
        ]
    }
}
