Hello:
Wondering if folks out there have switched over to "rotating API keys" for their MAUI/iOS/Android applications, especially for any public-facing applications? Are you asking users to sign in to AGOL (for public-facing applications, I couldn't imagine this being likely)? Or perhaps, you have a 'subscription service' and ask users to sign into your service first. Then, once signed in, you can pass back the key?
How are you storing the key:
Thanks for any insight on this. We're looking at options right now, and it'll be helpful to know how others are dealing with this. The Legacy keys expire in June, 2026, so need to figure this out fairly quickly. Thanks.
Thanks for the question Karen. We're actively looking into the topics you asked. We'll share when we come up with a cohesive plan.
A few notes:
Stay tuned for our future updates.
Thanks for responding. We've reached out to some folks at ESRI and hope to hear back soon.
Another thing too: It would be nice if the .NET Maps SDK API supported 'referrers' in requests (ie. ArcGISPortal.CreateAsync(siteUri, referrer). That could theoretically be used to provide a bit more security.
And we will definitely change our API Key length to a longer length.
I'll respond as well if I get additional insight. Thanks again.