@techreport{ietf-httpapi-privacy-06, number = {draft-ietf-httpapi-privacy-06}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-httpapi-privacy/06/}, author = {Rich Salz and Mike Bishop and Marius Kleidl}, title = {{Protecting Credentials with HTTP APIs}}, pagetotal = 9, year = 2026, month = may, day = 11, abstract = {Redirecting HTTP requests to HTTPS is a common pattern for human- facing web resources. When done for authenticated HTTP API traffic, client credentials are exposed to the network. This document discusses the pitfalls of the redirect approach and makes deployment recommendations for authenticated HTTP APIs. It does not specify a protocol.}, }