Your public API has no login — and no identity
Browsing without signing in is the requirement. Trusting the header was the bug.
What you'll learn
- An Origin or X-Client-App header is a string the caller chooses, so it authenticates a channel, not a caller.
- A short-lived guest token gives an anonymous request a countable, expiring, revocable identity without any account behind it.
- Rate-limit on the token subject rather than the IP: addresses rotate hourly on a proxy pool and a whole office shares one behind NAT.
Share this passage
Drawing…
Understand it one step at a time
The short runs these in order in about 26 seconds. Here they are written out — pick any step to jump the short straight to it.
Browsing without a login was the requirement
Search and browse before sign-in is a deliberate product decision, and the right one. Nobody creates an account to see a menu.
Frequently asked questions
- How can a mobile app call an API without a login?
- It asks your API for a token of its own before the user does anything. Your API issues a short-lived guest JWT scoped to read-only endpoints. The user never sees a login screen, but every request still carries an identity you can rate-limit and revoke.
- Is checking the Origin header enough to secure a public API?
- No. Origin and Referer are ordinary request headers, so any curl command can set them to whatever your server expects. CORS is enforced by the browser to protect the user, not by your server to protect your data.
Free app · no app store
These are built for a phone
Every short is drawn at full portrait height, the shape a phone already is. Installed, it opens full-bleed with no address bar across the top — and the whole library reads offline.
Read deeper on Azure
Twenty seconds gets the shape of an idea across. These go into how it behaves in production.
-
Browsing Without a Login Was the Requirement: How to Secure a Public API on Azure
Browsing products without login was a real requirement. Trusting requests because they came from our own app was the bug, and curl does not care.
-
AI Bot Attacks on a Mobile App Login, and How Azure Stops Them
A script tries 8,000 passwords a minute against your login API at 3am. Rate limiting, smart lockout and Defender for Cloud make speed the losing move.
-
Azure Key Vault Explained: The One Secret Tutorials Never Remove
Moving every secret into Key Vault leaves exactly one behind: the credential that opens the vault. A managed identity is what removes it.
More shorts
-
Azure
Money debited. Order failed.
10 steps · 56s
-
Azure
One tap. Two orders.
10 steps · 57s
-
Azure
1.6 million downloads. One photo.
10 steps · 58s
Get new posts by email
New technical articles, Azure AI and GitHub Copilot updates, and upcoming events. No spam, unsubscribe anytime.