Protection of API from abuse (signup and carding attacks)
I have a backend (API) and mobile apps.
Mobile apps user use same client_id (Oauth2).
Now I see many Bots signing up, adding credit card for checking them (carding)
I cannot throttle, limit them since the IP is always different also client… Continue reading Protection of API from abuse (signup and carding attacks)