XenForo 2.3 allows to create API keys and configure the scopes they can be used for.
However it is not possible to restrict them to specific IP addresses or specify a start and / or expiry date.
Being able to restrict API keys in such a way could strenghten security, especially if the API is used to connect other (internal) services / apps.
XenForo 2.3 will add OAuth2 clients that will also use API scopes.
I therefore suggest to make it possible to restrict API keys and OAuth2 clients to specific IP addresses / CIDR and allow to set a start and / or expiry date.
				
			However it is not possible to restrict them to specific IP addresses or specify a start and / or expiry date.
Being able to restrict API keys in such a way could strenghten security, especially if the API is used to connect other (internal) services / apps.
XenForo 2.3 will add OAuth2 clients that will also use API scopes.
I therefore suggest to make it possible to restrict API keys and OAuth2 clients to specific IP addresses / CIDR and allow to set a start and / or expiry date.
		
		Upvote
		18
		
	
			