IP Library › Granted Patent US 12,748,580
Granted Patent B2
US 12,748,580 · App. 18/428,651 · Granted Sep 29, 2026

Authorization identifiers with executable code blocks

Inventors: Amitesh Madhur (Fremont, CA); Shubham Kumar (San Jose, CA); Divya Venkatachalam (San Jose, CA); Praveen Yedlapalli (Austin, TX)
Assignee: NUTANIX, INC.
G06F8/42G06F9/541
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,748,580
App. No.
18/428,651
Filed
Jan 31, 2024
Granted
Sep 29, 2026
Kind
B2
Art Unit
2191
USPC
717/143
Abstract

Techniques using authorization identifiers with code blocks include one or more non-transitory computer-readable media storing program instructions that, when executed by one or more processors of an authorization server, cause the one or more processors to perform a method including receiving, from an application programming interface (API) server, an authorization request, the authorization request including an API authorization identifier; determining whether the API authorization identifier is valid; and in response to determining that the API authorization identifier is valid: executing a code block in the API authorization identifier; adding an output generated by the execution of the code block to a response to the authorization request; and returning the response to the API server.

Claims (56)

1 . One or more non-transitory computer-readable media storing program instructions that, when executed by one or more processors of an authorization server, cause the one or more processors to perform a method comprising:

receiving, from an application programming interface (API) server, an authorization request, the authorization request including an API authorization identifier, the API authorization identifier comprising an authentication identifier and an executable code block separate from the authentication identifier;

determining whether the API authorization identifier is valid based on the authentication identifier; and

in response to determining that the API authorization identifier is valid:

executing the executable code block;

adding an output generated by the execution of the executable code block to a response to the authorization request; and

returning the response to the API server.

2 . The one or more non-transitory computer-readable media of claim 1 , wherein the output generated by the executing of the executable code block includes business data of a client associated with the API authorization identifier.

3 . The one or more non-transitory computer-readable media of claim 1 , wherein executing the executable code block comprises executing the executable code block within a container instance.

4 . The one or more non-transitory computer-readable media of claim 1 , wherein the method further comprises validating the executable code block before executing the executable code block.

5 . The one or more non-transitory computer-readable media of claim 4 , wherein the method further comprises in response to the executable code block failing the validating, adding a code block error to the response to the authorization request.

6 . The one or more non-transitory computer-readable media of claim 4 , wherein validating the executable code block comprises validating a syntax of the executable code block.

7 . The one or more non-transitory computer-readable media of claim 4 , wherein validating the executable code block comprises determining that each function call in the executable code block is included in a white list of permitted function calls.

8 . The one or more non-transitory computer-readable media of claim 4 , wherein validating the executable code block comprises determining whether a client associated with the API authorization identifier has exceeded a quota of a number of executable code blocks that can be executed over a time period.

9 . The one or more non-transitory computer-readable media of claim 1 , wherein the method further comprises in response to the API authorization identifier failing the validating, returning an error to the API server.

10 . The one or more non-transitory computer-readable media of claim 1 , wherein the API authorization identifier is provided by a client requesting access to a service provided by the API server.

11 . The one or more non-transitory computer-readable media of claim 1 , wherein the output generated by the executing of the executable code block is added to a response returned to a client that provided the API authorization identifier.

12 . The one or more non-transitory computer-readable media of claim 1 , wherein the authentication identifier is a key, a token, or a certificate.

13 . A computer-implemented method of processing an authorization request, the computer-implemented method comprising:

receiving, from an application programming interface (API) server, an authorization request, the authorization request including an API authorization identifier, the API authorization identifier comprising an authentication identifier and an executable code block separate from the authentication identifier;

determining whether the API authorization identifier is valid based on the authentication identifier; and

in response to determining that the API authorization identifier is valid:

executing the executable code block in the API authorization identifier;

adding an output generated by the execution of the executable code block to a response to the authorization request; and

returning the response to the API server.

14 . The computer-implemented method of claim 13 , wherein the output generated by the executing of the executable code block includes business data of a client associated with the API authorization identifier.

15 . The computer-implemented method of claim 13 , wherein executing the executable code block comprises executing the executable code block within a container instance.

16 . The computer-implemented method of claim 13 , further comprising validating the executable code block before executing the executable code block.

17 . The computer-implemented method of claim 16 , further comprising in response to the executable code block failing the validating, adding a code block error to the response to the authorization request.

18 . The computer-implemented method of claim 16 , wherein validating the executable code block comprises validating a syntax of the executable code block.

19 . The computer-implemented method of claim 16 , wherein validating the executable code block comprises determining that each function call in the executable code block is included in a white list of permitted function calls.

20 . The computer-implemented method of claim 16 , wherein validating the executable code block comprises determining whether a client associated with the API authorization identifier has exceeded a quota of a number of code blocks that can be executed over a time period.

21 . The computer-implemented method of claim 13 , further comprising in response to the API authorization identifier failing the validating, returning an error to the API server.

22 . The computer-implemented method of claim 13 , wherein the API authorization identifier is provided by a client requesting access to a service provided by the API server.

23 . The computer-implemented method of claim 13 , wherein the output generated by the executing of the executable code block is added to a response returned to a client that provided the API authorization identifier.

24 . The method of claim 13 , wherein the authentication identifier is a key, a token, or a certificate.

25 . A system comprising:

a memory storing instructions; and

one or more processors coupled to the memory and, when executing the instructions, are configured to perform operations comprising:

receiving, from an application programming interface (API) server, an authorization request, the authorization request including an API authorization identifier, the API authorization identifier comprising an authentication identifier and an executable code block separate from the authentication identifier;

determining whether the API authorization identifier is valid based on the authentication identifier; and

in response to determining that the API authorization identifier is valid:

executing the executable code block in the API authorization identifier;

adding an output generated by the execution of the executable code block to a response to the authorization request; and

returning the response to the API server.

26 . The system of claim 25 , wherein the output generated by the executing of the executable code block includes business data of a client associated with the API authorization identifier.

27 . The system of claim 25 , wherein executing the executable code block comprises executing the executable code block within a container instance.

28 . The system of claim 25 , wherein the operations further comprise validating the executable code block before executing the executable code block.

29 . The system of claim 28 , wherein the operations further comprise in response to the executable code block failing the validating, adding a code block error to the response to the authorization request.

30 . The system of claim 28 , wherein validating the executable code block comprises validating a syntax of the executable code block.

31 . The system of claim 28 , wherein validating the executable code block comprises determining that each function call in the executable code block is included in a white list of permitted function calls.

32 . The system of claim 28 , wherein validating the executable code block comprises determining whether a client associated with the API authorization identifier has exceeded a quota of a number of code blocks that can be executed over a time period.

33 . The system of claim 25 , wherein the operations further comprise in response to the API authorization identifier failing the validating, returning an error to the API server.

34 . The system of claim 25 , wherein the API authorization identifier is provided by a client requesting access to a service provided by the API server.

35 . The system of claim 25 , wherein the output generated by the executing of the executable code block is added to a response returned to a client that provided the API authorization identifier.

36 . The system of claim 25 , wherein the authentication identifier is a key, a token, or a certificate.

Assignments (3)
SECURITY INTEREST Recorded Feb 13, 2025
From: NUTANIX, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 070206/0463 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME TO BE LISTED AS PRAVEEN YEDLAPALLI PREVIOUSLY RECORDED AT REEL: 66323 FRAME: 698. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 16, 2024
From: MADHUR, AMITESH; KUMAR, SHUBHAM; VENKATACHALAM, DIVYA; YEDLAPALLI, PRAVEEN
To: NUTANIX, INC.
Reel/Frame 066618/0629 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2024
From: MADHUR, AMITESH; KUMAR, SHUBHAM; VENKATACHALAM, DIVYA; YEDAPALLI, PRAVEEN
To: NUTANIX, INC.
Reel/Frame 066323/0698 →
Continuity (2)
Provisional Application 63606362 · Dec 5, 2023
Related Publication 20250181332A1 · Jun 5, 2025
References Cited (62)
US 6529943B1 · Ohi · 2003 [cited by examiner]
US 8549518B1 · Aron et al. · 2013 [cited by applicant]
US 8601473B1 · Aron et al. · 2013 [cited by applicant]
US 8782744B1 · Fuller et al. · 2014 [cited by applicant]
US 8850130B1 · Aron et al. · 2014 [cited by applicant]
US 8863124B1 · Aron · 2014 [cited by applicant]
US 9009106B1 · Aron et al. · 2015 [cited by applicant]
US 9069708B2 · Gill et al. · 2015 [cited by applicant]
US 9336132B1 · Aron et al. · 2016 [cited by applicant]
US 9652265B1 · Narayanasamy et al. · 2017 [cited by applicant]
US 9747287B1 · Bhardwaj et al. · 2017 [cited by applicant]
US 9772866B1 · Aron et al. · 2017 [cited by applicant]
US 9823950B1 · Carrier · 2017 [cited by examiner]
US 11178128B2 · Poschel et al. · 2021 [cited by applicant]
US 20100146291A1 · Anbuselvan · 2010 [cited by examiner]
US 20120167121A1 · Reierson et al. · 2012 [cited by applicant]
US 20140136346A1 · Teso · 2014 [cited by examiner]
US 20150092233A1 · Park · 2015 [cited by examiner]
US 20160014084A1 · Hansen · 2016 [cited by applicant]
US 20170199766A1 · Wagner · 2017 [cited by examiner]
US 20170228711A1 · Chawla · 2017 [cited by examiner]
US 20170366551A1 · Brandwine · 2017 [cited by applicant]
US 20180083971A1 · Brown et al. · 2018 [cited by applicant]
US 20180129816A1 · Schmidt · 2018 [cited by examiner]
US 20200322324A1 · Chang et al. · 2020 [cited by applicant]
US 20210233126A1 · Weerapurage · 2021 [cited by examiner]
US 20230058273A1 · Sundar · 2023 [cited by examiner]
US 20230067552A1 · Caudill et al. · 2023 [cited by applicant]
CN 111538977A · 2020 [cited by examiner]
CN 113821783A · 2021 [cited by examiner]
DE 102014119363A1 · 2015 [cited by examiner]
Poitras, Steven. “The Nutanix Bible” (Oct. 15, 2013), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 11, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 20, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive. org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 7, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 4, 2015), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 12, 2016), from https://nutanixbible.com/ ; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2016), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 3, 2017), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 8, 2017), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 3, 2018), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 25, 2018), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 8, 2019), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jul. 25, 2019), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 17, 2019), from https://nutanixbible.com/; pp. all. [cited by applicant]
Cano, Ignacio et al. “Curator: Self-Managing Storage for Enterprise Clusters”; University of Washington; published Mar. 2017; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Mar. 2, 2020), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 1, 2020), from https://nutanixbible.com/; pp. all. [cited by applicant]
Ctirix Validated Solutions, “Citrix XenDesktop 7.1 on Microsoft Hyper-V Server 2012 R2 on Nutanix Virtual Computing Platform Solution Design”, Prepared by: Citrix Validated Solutions, Jun. 25, 2014. [cited by applicant]
Poitras, Steven et al., The Nutanix Bible—Classic Edition, Jan. 3, 2024, 282 pages, https://www.nutanixbible.com/pdf/classic.pdf. [cited by applicant]
“Configure Logical API for Multiple APIs”, https://auth0.com/docs/get-started/apis/set-logical-api, Nov. 21, 2023, 10 pages. [cited by applicant]
“Google scripts API”, https://developers.google.com/apps-script/api/concepts, Nov. 21, 2023, 2 pages. [cited by applicant]
“How to execute Script API faster”, https://www.akana.com/blog/api-script, Nov. 21, 2023, 8 pages. [cited by applicant]
Zhong et al., “Distributed Blockchain-Based Authentication and Authorization Protocol for Smart Grid”, https://www.hindawi.com/journals/wcmc/2021/5560621/, Feb. 19, 2021, 15 pages. [cited by applicant]
“Authenticate for using client libraries” https://cloud.google.com/docs/authentication/client-libraries, Jan. 25, 2024, 3 pages. [cited by applicant]
“Authenticate by using API keys” https://cloud.google.com/docs/authentication/api-keys#using-with-client-libs, Jan. 25, 2024, 12 pages. [cited by applicant]
“Client-side Integrations with Custom API Keys”, https://www.serviceobjects.com/blog/client-side-integrations-with-custom-api-keys/, Feb. 4, 2021, 7 pages. [cited by applicant]
Forshaw, Aden, “A Brief Guide on How & Why to Secure API Keys”, https://theauthapi.com/articles/a-brief-guide-on-how-why-to-secure-api-keys/, May 11, 2022, 12 pages. [cited by applicant]
“Manage API keys”, https://docs.coveo.com/en/1718/manage-an-organization/manage-api-keys, Jan. 25, 2024, 9 pages. [cited by applicant]
“How to Use API Keys”, https://coding-boot-camp.github.io/full-stack/apis/how-to-use-api-keys, Nov. 14, 2023, 8 pages. [cited by applicant]
Extended European Search Report for Application No. 24217492.8 dated Mar. 31, 2025. [cited by applicant]