Best Software for 2025 is now live!
George-Marius D.
GD
Software Engineer at UiPath

How do you prevent end users for getting access to a plain text auth token?

My plan is to have an app that communicates directly with Nordigen. But this means end users need access to secret keys, I knoe this is a bad practice and I think in the end I will put Nordigen behind a proxy that authenticates end users.
1 comment
Looks like you’re not logged in.
Users need to be logged in to answer questions
Log In
GoCardless Bank Account Data
Official Response
GoCardless Bank Account Data
Madara S.
MS
Democratising PSD2 Data @ Nordigen | Fintech | Open Banking
0
Hi George, It would be more optimal to put Nordigen behind a proxy that authenticates end users (as you write yourself). In the more medium term, Nordigen also has user level permissions on our roadmap, that would be another way how such situations could be solved.
Looks like you’re not logged in.
Users need to be logged in to write comments
Log In
Reply