Secure API Design
Object-level authorisation, input validation and safe error responses.
6 to work through
-
intermediate
A developer platform's API is used by thousands of external integrators. What security properties must be defaults rather than options?
2 min answer -
advanced
A marketplace API is used by sellers, buyers, internal services and third-party tools. Which security properties must be enforced at the API layer, and which must not be?
2 min answer -
advanced
How would you make it structurally impossible for a developer to add an endpoint that returns another tenant's data?
2 min answer -
advanced
In March 2023 OpenAI disclosed that a bug in the redis-py async client let one request receive data left behind in a recycled connection, so some users saw other users' chat titles and some payment details. The authorisation code was not at fault. Which class of control was missing, and what would you change?
3 min answer -
advanced
Review this design. Every one of 40 API endpoints checks that the caller owns the requested resource by fetching it and comparing an owner field in the controller. A penetration test found one endpoint missing the check. What would you change and what would you leave alone?
3 min answer -
advanced
You are reviewing a new public API before launch. What do you check, in priority order?
2 min answer
3 terms in this topic
Mass Assignment
A vulnerability where a request body is bound directly to an internal object, allowing a caller to set fields the API never intended to expose.
patternRequest-Scoped Identity
Binding every piece of shared mutable state a response is assembled from to the principal who asked for it, so that a bug in pooling or caching produ…
practiceSecure API Design
Building an interface where the safe path is the default and the unsafe one requires deliberate effort.
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.