Exploring Approaches to Authentication in REST API
Kerimalieva, Zarina · Zenodo (CERN European Organization for Nuclear Research) · 2025
This research presents an empirical framework for authentication method se-lection in REST API architectures through systematic quantitative analysis ofsecurity-performance tradeoffs. We conduct comprehensive experimental evalua-tion of three authentication paradigms—Basic Authentication, JSON Web Tokens(JWT), and OAuth 2.0—implemented within Spring Security framework. Ourmethodology employs rigorous load testing, security vulnerability assessment, andcomplexity analysis to establish measurable criteria for architectural decision-making. Results demonstrate that JWT achieves optimal performance with 53%higher throughput than Basic Authentication and 77% higher than OAuth 2.0,while OAuth 2.0 provides superior security with comprehensive token manage-ment capabilities. We introduce a novel decision matrix that quantifies tradeoffsacross security, performance, and implementation dimensions, enabling evidence-based authentication strategy selection. The framework’s validation shows 87%accuracy in method recommendation compared to 61% for expert heuristic ap-proaches, providing significant improvement in architectural decision quality.