I noticed the limit on API requests is limited per IP not per API key. If my app gets a lot of traffic then it seems like this would suggest my requests should all come from my users instead of from my server.
However, if I generate the request from the client, how can I protect my API key?
Thanks!
Un film, une émission télévisée ou un artiste est introuvable ? Connectez-vous afin de créer une nouvelle fiche.
Vous souhaitez évaluer ou ajouter cet élément à une liste ?
Pas encore membre ?
Réponse de Travis Bell
le 24 juillet 2013 à 18h49
Hi johnb003 ,
It depends what kind of client you are building. For any desktop or mobile application, your API key can be compiled in to your app and would never be visible to the public. If you're building an HTML based project, there isn't much of a way to obfuscate it. Make a note that API keys are free and to head over to TMDb to get one is the best you can probably do.
Réponse de johnb003
le 24 juillet 2013 à 19h58
It's for http, and mobile. Is it ok if I maintain a clone of the db, as long as I don't cache the images? I didn't find anything in the Eula that prevented this, but I guess it's good to double check.
After all you do have the changes api which makes it very nice and convenient to maintain such a clone.
Réponse de Travis Bell
le 25 juillet 2013 à 10h23
As long as you attribute TMDb as the source of the data you're fine to go ahead and do that.