I\'m using API keys to secure an ASP.NET Core 2.2 API. Info about my allowed clients is loaded from appsettings and I have middleware that retrieves the key from the request