RODiT is a token-based framework to manage authentication, authorization, configuration and licensing of API in a unified lifecycle.
- It implements a trust model (triangle of trust) via DNS authorisations to prevent rogue credential issuers.
- It decouples key rotation from license expiration, allowing flexible lifecycle management.
Overall, it helps users authenticate on various services using the features of NEAR Protocol while preserving their privacy.
RODiT gives API users and service-providers a simplified, more secure, and more flexible way to acquire and manage credentials and API services.
- It reduces the complexity and cost of registration, configuration and licensing API workflows.
- It enhances security through mutual authentication, blockchain token uniqueness, and endpoint-local key generation.
API providers enjoy less credential-sharing risk as RODiT cannot easily be shared without losing it.
