|
|
|
|
|
by kiranravi1995
3 days ago
|
|
We built ours stateless before the spec allowed it. No SSE at all and GET just returns 405, everything is a plain POST about 46 tools. We were betting clients would cope, and most of them did. When one did not, we had to tell the user their client was the problem, which is never a good look. The surprise for us was auth getting easier. No session means no confusion about when the key was checked. Anyone can list the tools and actually calling one needs a bearer token or you get a 401. |
|