Publishing an API endpoint
In Peliqan, go to the Build section, and click the ”+” icon when hovering over “API endpoints”:- JWT Authorization: create a JWT web token under Settings > Security, and use this in the Authorization header to authenticate when consuming this API endpoint.
- Public: no authorization, use this when you implement your own authentication scheme with e.g. multiple API keys (see below)
Adding a Python script to handle API requests
In Peliqan, go to the Build section, and click the ”+” icon when hovering over “Apps”. Add a script (app) of type “API endpoint handler”:Implement custom API keys using the Peliqan Secret Store
In order to distribute individual API keys to multiple consumers of your API, you can use the Peliqan Secret Store to store them in a secure manner, and validate them in your API handler script. In the below example we add a new Secret Store for each consumer of the API. For example if you have 5 consumers, you will add 5 Secret Stores. Step 1: Create an API key and save it in a Secret Store. In Peliqan, go to “Connections”, click on “Add new connection” and select “Secret Store”. Give it a name, e.g. the name of your consumer and enter a key. Note down the API key first and communicate it to the consumer.pq.get_secret('<connection_name>') to retrieve and verify the API key used in the API request, e.g. from the X-Api-Key header.
Example code:
Implementing custom authentication with automated creation & encryption of API keys
Below is an example API handler script, to implement your own authentication mechanism with a high amount of API keys, that are stored encrypted in a table. In this scenario, the API keys can be created automatically from a script (e.g. for each user in a database). This allows you to distribute individual API keys to multiple consumers of your API and e.g. apply row-level data access. The encryption key (your secret to encrypt & decrypt API keys) can be stored in the Peliqan Secret Store and retrieved usingpq.get_secret("<connection_name>"). Add a connection of type “Secret Store”, set an encryption key as the value and give it a name e.g. “Encryption secret”.
You can add a new API key using the function add_new_api_key() from a separate script. Make sure to create a table named api_keys first (in schema api_keys), with an “id” column and a “api_key” (string) column.
The API key can be set in the Authorization header when calling your API endpoint. If a valid API key is used, the api key id will be retrieved. You can apply permissions based on the api key id before sending a response. For example you can filter data based on the api key id (row level permissions).
Click here to see the API handler script
Click here to see the API handler script
