You can use OAuth, AuthSub, or ClientLogin. ClientLogin is simplest (it just uses a username/password), but discouraged because it requires users to turn over .