<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-httpapi-privacy" target="https://datatracker.ietf.org/doc/html/draft-ietf-httpapi-privacy-06">
   <front>
      <title>Protecting Credentials with HTTP APIs</title>
      <author initials="R." surname="Salz" fullname="Rich Salz">
         <organization>Akamai Technologies</organization>
      </author>
      <author initials="M." surname="Bishop" fullname="Mike Bishop">
         <organization>Akamai Technologies</organization>
      </author>
      <author initials="M." surname="Kleidl" fullname="Marius Kleidl">
         <organization>Transloadit</organization>
      </author>
      <date month="May" day="11" year="2026" />
      <abstract>
	 <t>   Redirecting HTTP requests to HTTPS is a common pattern for human-
   facing web resources.  When done for authenticated HTTP API traffic,
   client credentials are exposed to the network.  This document
   discusses the pitfalls of the redirect approach and makes deployment
   recommendations for authenticated HTTP APIs.  It does not specify a
   protocol.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-httpapi-privacy-06" />
   
</reference>
