Documentation / API Security

API Authentication และ Security

ตั้ง secure API access: เลือก authentication method, ป้องกัน requests ด้วย signature, แยก permissions, จำกัด network access และจัด activity monitoring

เปิด API requirements
การเข้าถึง
connection verification
Signature
request protection
Roles
permission separation
Control
activity history
Security model

ปกป้องทุกชั้นของ API

01
Connection verification

ใช้ API key, OAuth 2.0, JWT หรือ service account แยกสำหรับแต่ละ connected service

02
Request verification

Signature, send time, unique identifier และ replay protection

03
Authorization check

Roles, permissions, IP addresses, environment และ operation restrictions ที่อนุญาต

04
History และ control

Request ID, initiator, result, alerts และ incident procedure

ภาพรวม

API security สร้างจากการป้องกันหลายชั้น

API key อย่างเดียวไม่พอ โครงสร้างที่เชื่อถือได้ต้องตรวจ connected service, request integrity, permission ของ operation, allowed network source และเก็บ activity history

Connection verification

แต่ละ service, partner, provider และ environment ใช้ keys และ account แยกกัน

Request integrity

Signature, send time และ unique identifier ป้องกัน request จากการแก้ไขและ replay

Activity history

Log เชื่อม request, initiator, executed operation, result และ subsequent changes

Authentication

วิธีเลือก authentication method

การเลือกขึ้นอยู่กับประเภท integration, จำนวน connections, access lifetime และความจำเป็นในการมอบ permissions แยก

API keys

เหมาะกับ direct system-to-system exchange เมื่อแต่ละ client และ environment มี key แยก

OAuth 2.0

เหมาะกับ managed access ที่มี limited permissions, short lifetime และ centralized revocation

JWT

ส่งข้อมูล issuer/owner, recipient, expiry และ permissions โดยต้องตรวจ signature

Service accounts

ช่วยแยก automated processes, system permissions และความรับผิดชอบของแต่ละ integration

อย่าใช้ access เดียวกับหลาย systems

Separate keys และ accounts ช่วยจำกัดหรือปิด integration หนึ่งได้โดยไม่หยุด modules อื่น

Request signing

Request signing และ replay protection

Signature ยืนยัน source ของ request และช่วยตรวจว่าข้อมูลไม่ถูกแก้หลังส่ง

01

ประกอบ request data

รวม HTTP method, path, parameters, send time, unique identifier และ body checksum ตามลำดับที่ตกลง

02

สร้าง signature

คำนวณ HMAC หรือ digital signature ด้วย assigned secret หรือ private key

03

ตรวจเวลาและ uniqueness

ปฏิเสธ expired request, repeated identifier และ operation ที่ถูกประมวลผลแล้ว

04

เปรียบเทียบ signature อย่างปลอดภัย

สร้าง request data ซ้ำฝั่ง receiver แล้วเปรียบเทียบ calculated signature กับที่ได้รับ

Access และ roles

Network access, roles และ key lifetime

หลังตรวจ connection แล้ว API จะระบุ request source, allowed operation และ validity ของ access ใน environment ที่เลือก

Allowed IP addresses

รายการ allowed addresses และ subnets สำหรับ API, incoming events และ admin access

Roles

แยก operator, finance, admin และ system permissions

Permissions

สิทธิ์ขั้นต่ำที่จำเป็นสำหรับ read, data change, payouts, reports หรือ player management

Environment separation

Test และ production ใช้ endpoints, keys, incoming events และ datasets ต่างกัน

Expiry

Temporary access และ short-lived tokens ลดความเสี่ยงจาก stale keys

Planned key rotation

Old และ new key อาจใช้งานพร้อมกันช่วง transition สั้น ๆ

Rate limiting

Request rate จำกัดตาม client, operation, role และ risk level

Fast revocation

Key, token, role หรือ IP address สามารถปิดได้โดยไม่กระทบ integrations อื่น

Data protection

การปกป้อง personal, gaming และ financial data

API ส่งเฉพาะข้อมูลที่จำเป็น และ storage/display rules ต้องคำนึงถึง sensitivity

Storage และ processing

Encrypt sensitive data และ secrets at rest
Mask tokens, payment details และ personal data ใน interfaces
จำกัด retention period และลบ service data อย่างปลอดภัย
แยก production และ test data โดยไม่คัดลอกข้อมูลเกินจำเป็น

Transmission และ minimization

ใช้ TLS สำหรับ API connections, incoming events และ admin access ทั้งหมด
ส่งเฉพาะ fields ที่จำเป็นต่อ operation นั้น
ห้ามส่ง secrets, tokens และ sensitive data ใน URL หรือ standard logs
Filter data ตอน export, diagnostics และ support requests
Control และ audit

Secure operations, audit และ response

หลัง launch ความปลอดภัยต้องรักษาด้วย event monitoring, regular permission review, anomaly detection และ incident procedure ที่ชัดเจน

Activity log

Initiator, request ID, operation, time, result, status change และ decision reason

State monitoring

Login failures, invalid signatures, rising rejects, delays และ unusual activity ของ connected service

Security alerts

Alerts สำหรับ repeated requests, activity spikes, blocked IPs และ critical actions

Incident response

จำกัด access, revoke keys, preserve history, recover และแจ้งผู้รับผิดชอบ

Security testing

Expired tokens, invalid signatures, wrong permissions, repeated requests และ attempts to bypass restrictions

Access review

ตรวจ active keys, accounts, roles, IP addresses และ unused permissions เป็นประจำ

ตรวจสอบก่อน production launch

Production access จะออกหลังตรวจ login methods, request signing, permissions, logging และ response plan

สร้าง access keys แยกสำหรับ test และ production
ตรวจ signature, send time และ replay protection แล้ว
Roles และ permissions จำกัดเฉพาะ operations ที่จำเป็น
ยืนยัน allowed IPs, TLS และ incoming event endpoints แล้ว
Secrets ไม่เข้า URLs, standard logs หรือ client-side code
ตั้ง logs, alerts, key rotation และ access revocation procedure แล้ว

ต้องการตั้ง secure API access ไหม

ส่งข้อมูล connected systems, users, environments, critical operations และ data requirements มาให้ APIACE จะช่วยกำหนด access และ protection model ที่เหมาะสม