access token should do the trick. See http://websec.io/2013/02/14/API-Authentication-Public-Private-Hashes.html add https would be better though