1. A username and password must be used to authenticate all requests to the API.

  2. All requests must be sent over HTTPS.

  3. All requests use basic HTTPS authentication.

  4. Content-Type must be set to application/json.