This type of authentication is commonly used for server-to-server interactions. Lobyco implements OAuth 2.0 client credentials flow using Microsoft identity platform.
Lobyco creates an Azure App registration and share credentials with customer.This setup is recommended for scenarios where customers don’t operate their own Azure AD tenants.
Customer imports Lobyco multi-tenant Azure AD app into their local tenant, and creates Azure App registration which enables full control over the secrets.This setup is recommended for scenarios where customers operate their own Azure AD tenants.
While an API key alone isn’t the most robust form of authentication, it can still be useful in specific scenarios. For instance, in POS systems, where implementing efficient token management - such as caching and renewing tokens before expiration can be challenging, an API key might offer a practical solution.As additional security measure, only specific IP addresses can be whitelisted to access Lobyco APIs.