• Spotify has vaguely attributed the need for the API changes to improving security:

    • In its blog post, Spotify says that it rolled out the changes with “the aim of creating a more secure platform.”
    • In a community forum post, a Spotify employee says that “we want to reiterate the main message from the blog that we’re committed to providing a safe and secure environment for all Spotify stakeholders.” The post has many pages of replies from frustrated developers.
    • In a statement to The Verge, Spotify spokesperson Brittney Le Roy says that “as part of our ongoing work to address the security challenges that many companies navigate today, we’re making changes to our public APIs.”

    This is fairly disingenuous. The affected endpoints are all GET requests, which are read-only requests that provide some data about the track/artist/playlist/etc. There isn’t really very much potential to do anything insecure here.

    The only thing they’re securing is their hegemony.