REFERENCE
Sending A Secret Versus Proving You Hold One
The Authorization header has one grammar — a scheme token, a space, then
credentials in whatever shape the scheme defines — and wildly different security properties
behind it. The distinction that matters in practice is the one the table above is built around:
what does an attacker get by reading a single request?
For the top three, everything. Basic carries the password in a form that decodes in one step,
Bearer carries a token that is replayable until it expires, and an API key is usually valid until
somebody rotates it by hand. For the bottom three, nothing reusable. Digest, SigV4 and a
well-designed HMAC scheme all send proof that you hold a secret rather than the secret
itself, which is why SigV4 goes to the trouble of a canonical request: signing the method, host,
path, query, headers and a hash of the body means a captured signature cannot be moved to a
different request. An in-house HMAC scheme is only as good as its canonical string — sign a
timestamp and you get replay protection, sign the body hash and you get integrity, sign only the
path and you have built Basic auth with extra steps.