Possible Duplicate:
Restful API authentication recommendation?
I'm writing an API in PHP and it opted to use Respect/REST.
This is not a public API, ie, only authorized client applications can consume there. And this is where I would like some idea of how to guarantee the security of information that the API handles. The client applications can be written in any language, but as I said, they should be allowed to use the API.
At the moment I'm writing a test client for this API using jQuery.rest.
My doubts are:
1) How to ensure that only authorized clients can access the API?
2) How to ensure that every request made to the API has been authorized client?