You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Azure API Management中实现可撤销API密钥的第三方认证方案咨询

Azure APIM 基于自有认证服务器的API密钥验证方案实现

这个方案完全可行,不少团队都在服务器间认证场景中采用过类似实现,正好匹配你需要的「可撤销永久API密钥+网关完成全认证流程」的需求。下面是具体的实现思路和策略示例:

核心实现逻辑

通过APIM的策略组合,完成「缓存优先→密钥验证→结果判定」的流程,全程在网关上处理,无需后端微服务介入:

  1. 提取请求中的API密钥
    从请求头(比如约定的X-API-Key)提取密钥,存入变量供后续使用。

  2. 优先检查本地缓存
    用APIM的缓存功能存储已验证过的有效密钥,避免频繁调用认证服务器,提升性能。

  3. 调用自有认证服务器验证
    缓存未命中时,通过send-request策略向你的认证服务器发送验证请求,传递待校验的API密钥。

  4. 根据验证结果控制访问
    若认证服务器返回成功状态码(如200),则允许请求转发到后端;若返回失败(如401/403),直接在APIM层返回拒绝响应,同时将有效结果存入缓存。

策略代码示例

<!-- 提取API密钥到变量 -->
<set-variable name="apiKey" value="@(context.Request.Headers.GetValueOrDefault("X-API-Key", ""))" />

<!-- 检查缓存中是否存在已验证的密钥 -->
<lookup-value key="@(context.Variables["apiKey"])" variable-name="isValidKey" cache-id="api-key-cache" />

<!-- 如果缓存未命中,调用认证服务器验证 -->
<choose>
    <when condition="@(context.Variables.GetValueOrDefault<bool?>("isValidKey") == null)">
        <!-- 发送验证请求到自有认证服务器 -->
        <send-request mode="new" response-variable-name="authResponse" timeout="20" ignore-error="false">
            <set-url>https://your-auth-server.com/api/validate-key</set-url>
            <set-method>POST</set-method>
            <set-header name="Content-Type" exists-action="override">
                <value>application/json</value>
            </set-header>
            <set-body>@{
                return new JObject(
                    new JProperty("apiKey", context.Variables["apiKey"])
                ).ToString();
            }</set-body>
        </send-request>

        <!-- 解析认证响应,判断是否有效 -->
        <set-variable name="isValidKey" value="@(((IResponse)context.Variables["authResponse"]).StatusCode == 200)" />

        <!-- 将验证结果存入缓存,设置过期时间(比如15分钟,平衡性能和撤销时效性) -->
        <cache-store-value key="@(context.Variables["apiKey"])" value="@(context.Variables["isValidKey"])" duration="900" cache-id="api-key-cache" />
    </when>
</choose>

<!-- 如果密钥无效,返回401拒绝访问 -->
<choose>
    <when condition="@(!context.Variables.GetValueOrDefault<bool>("isValidKey"))">
        <return-response>
            <set-status code="401" reason="Unauthorized" />
            <set-header name="WWW-Authenticate" exists-action="override">
                <value>API key</value>
            </set-header>
            <set-body>{"error": "Invalid or revoked API key"}</set-body>
        </return-response>
    </when>
</choose>

<!-- 验证通过,请求转发到后端服务 -->
<forward-request />

关键注意事项

  • 缓存时效性:缓存过期时间根据你的密钥撤销需求调整,比如设置15分钟,这样密钥被撤销后,最长15分钟内会失效,兼顾性能和实时性。
  • 认证服务器可靠性:给send-request添加重试策略,避免认证服务器临时故障导致请求失败,比如:
    <send-request mode="new" response-variable-name="authResponse" timeout="20" ignore-error="false">
        <!-- 原有配置 -->
        <retry condition="@(((IResponse)context.Variables["authResponse"]).StatusCode >= 500)" count="2" interval="1" first-fast-retry="true" />
    </send-request>
    
  • 安全防护:确保APIM与认证服务器之间用HTTPS通信,避免密钥在传输过程中泄露;同时限制认证服务器仅接受来自APIM的请求。
  • 日志监控:添加log-to-eventhub或trace策略,记录密钥验证的结果和相关请求信息,方便后续排查问题。

内容的提问来源于stack exchange,提问作者Fin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 14:50:26