Skip to content

Feature request: Token- or API-key–based auth for the DataCite REST API (in addition to Basic) #195

Description

@davidelbert

We use the DataCite REST API at https://api.datacite.org to mint DOIs and update metadata for our repository (PARADIM with prefix 10.34863). The API currently requires HTTP Basic auth with repository credentials for write operations. Please add support for token-based (e.g., OAuth2 access tokens or scoped Personal Access Tokens) and/or API-key authentication to improve security, auditability, and automation workflows.

Why this matters

  • Least privilege: scoped credentials (e.g., read:metadata, write:metadata, mint:dois) reduce blast radius versus a shared repository password.
  • Rotation and revocation: rotate/revoke a single token/key without impacting other integrations.
  • Auditability: attribute changes to a specific token/key rather than a shared Basic credential.
  • Precedent: DataCite already uses JWT tokens for the Usage Reports API; extending token auth to REST aligns with existing practice.

Proposed approach (backward-compatible)

  • Support Bearer tokens via Authorization: Bearer (short-lived OAuth2 access tokens and/or long-lived but scoped PATs).
  • Optionally support an API key header (e.g., X-API-Key: ), with per-key scopes and expiry.
  • Optionally allow constraints on credentials (limit to specific client-id and/or prefix).
  • Keep Basic auth working for ease of use or at least during transition (and document deprecation plan)

Example:

PUT /dois/10.1234/abcd
Authorization: Bearer eyJhbGciOi...
Content-Type: application/vnd.api+json

{ "data": { "type": "dois", "id": "10.1234/abcd",
  "attributes": { "contributors": [ ... ] } } }

Proposed acceptance criteria

  • REST endpoints accept Bearer tokens and (optionally) API keys in addition to Basic.
  • Tokens/keys can be issued with scopes and expiry; requests outside scope return 403.
  • Tokens/keys can be revoked server-side; revoked credentials are rejected within a bounded time.
  • Server logs/metrics capture a credential identifier to enable per-credential audit trails.
  • Documentation updated: auth methods, scopes, example requests, and migration guidance.

Thanks!

Activity

  1. locked and limited conversation to collaborators on Sep 26, 2025
  2. converted this issue into a discussion #196 on Sep 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions