# Confusion about API Authenticated User

**URL:** <https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042>\
**Category:** Development\
**Tags:** rest-api\
**Created:** [May 30, 2024, 11:37pm UTC](https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042 "2024-05-30T23:37:43Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)\
**Post date:** [May 31, 2024, 4:44am UTC](https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042/3 "2024-05-31T04:44:24Z")

</div>

> [@BrainFried](#):
>
> If my understanding is correct, isn’t this easy for a hacker to just modify the api-username in the header to retrieve chat discussions for any user?

You should never use that API from a frontend because in that case this indeed is a risk (actually the risk is much higher because the hacker can do anything)

You should do this from the backend.

If that is not an option then you should use User API keys instead.

---

_[View the full topic](https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042)._
