For more secure usage and scalability of the Whiteflag API, provide OAuth 2.0 as authentication mechanism, instead of only basic http auth. The Whiteflag API does not need to be an authentication server itself; it is may only act as the the resource owner / service provider.