We use the DataCite REST API at https://api.datacite.org to mint DOIs and update metadata for our repository (PARADIM with prefix 10.34863). The API currently requires HTTP Basic auth with repository credentials for write operations. Please add support for token-based (e.g., OAuth2 access tokens or scoped Personal Access Tokens) and/or API-key authentication to improve security, auditability, and automation workflows.
Why this matters
- Least privilege: scoped credentials (e.g., read:metadata, write:metadata, mint:dois) reduce blast radius versus a shared repository password.
- Rotation and revocation: rotate/revoke a single token/key without impacting other integrations.
- Auditability: attribute changes to a specific token/key rather than a shared Basic credential.
- Precedent: DataCite already uses JWT tokens for the Usage Reports API; extending token auth to REST aligns with existing practice.
Proposed approach (backward-compatible)
- Support Bearer tokens via Authorization: Bearer (short-lived OAuth2 access tokens and/or long-lived but scoped PATs).
- Optionally support an API key header (e.g., X-API-Key: ), with per-key scopes and expiry.
- Optionally allow constraints on credentials (limit to specific client-id and/or prefix).
- Keep Basic auth working for ease of use or at least during transition (and document deprecation plan)
Example:
PUT /dois/10.1234/abcd
Authorization: Bearer eyJhbGciOi...
Content-Type: application/vnd.api+json
{ "data": { "type": "dois", "id": "10.1234/abcd",
"attributes": { "contributors": [ ... ] } } }
Proposed acceptance criteria
- REST endpoints accept Bearer tokens and (optionally) API keys in addition to Basic.
- Tokens/keys can be issued with scopes and expiry; requests outside scope return 403.
- Tokens/keys can be revoked server-side; revoked credentials are rejected within a bounded time.
- Server logs/metrics capture a credential identifier to enable per-credential audit trails.
- Documentation updated: auth methods, scopes, example requests, and migration guidance.
Thanks!
We use the DataCite REST API at https://api.datacite.org to mint DOIs and update metadata for our repository (PARADIM with prefix 10.34863). The API currently requires HTTP Basic auth with repository credentials for write operations. Please add support for token-based (e.g., OAuth2 access tokens or scoped Personal Access Tokens) and/or API-key authentication to improve security, auditability, and automation workflows.
Why this matters
Proposed approach (backward-compatible)
Example:
Proposed acceptance criteria
Thanks!