How do you implement API key auth carefully?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
Store hashed keys, rotate them, bind to scopes, and rate limit.
WHY — Security instead of guessing?
Why interviewers care about Security:
question about Security.
trade-offs, and what you would actually do on a .NET project - not buzzwords.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1Store hashed keys, rotate
them, bind to scopes, and rate limit.
- 2Keys in query strings
leak via logs.
- 3Prefer headers and short-lived
tokens when possible.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
Store hashed keys, rotate them, bind to scopes, and rate limit. Keys in query strings leak via logs.