If they support it, I'd say use OAuth.
You don't store any credentials; they authenticate on the site and you get the access key which is what's used after they authenticate.
Although I don't know how you'd manage the initial login where you get the OAuth access key, which is what you use thereafter.
Last edited by lumpynose; 08-24-2019 at 04:45 PM.
|