Home / APIs and microservices / API security
API guide

API security

APIs expose your business logic and data directly. The most common API breaches are not clever hacks; they are missing checks, such as letting a logged-in user read someone else's record by changing an ID in the URL.

Top riskBroken object-level authorisation
IdentityOAuth 2.0 / OpenID Connect
PartnersKeys plus mTLS
KnowEvery API you expose

The risks that matter most

Based on the OWASP API Security Top 10 (2023).

RiskWhat it looks likeControl
Broken object-level authorisationChange /orders/1001 to /orders/1002 and see another customer's orderCheck ownership of every object in the service, not only at the gateway
Broken authenticationWeak tokens, keys in URLs, no expiryOAuth 2.0 / OIDC, short-lived tokens, mTLS for partners
Excessive data exposureThe API returns full records and the app hides fieldsReturn only the fields the caller needs
No rate limitsScraping, brute force, cost spikesLimits per caller at the gateway
Function-level authorisationA normal user can call admin endpointsSeparate admin APIs and check roles on every endpoint
Improper inventoryOld versions and test APIs still exposedAn API catalogue, and retire old versions on a schedule

Also essential

  • Validate every input against the API contract.
  • Log every call with caller identity, and alert on unusual patterns.
  • Test APIs for these risks before release, not after.
  • Keep secrets and keys out of code and front-end apps.

Untangling integrations, or opening APIs to partners?

Tell us which systems need to talk, who will call your APIs, and what breaks today. We will come back with a plain view of the right structure, what to change first, and what to leave alone.