Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

API security is the discipline of protecting the data and application logic exposed through an API. Start with authorization checks on every object, field, and operation; then add correctly implemented authentication, abuse controls, input and destination validation, hardened configuration, complete API inventory, and strict handling of third-party responses. The current OWASP API Security Top 10 edition is the 2023 list.

OWASP calls its list an awareness framework, not a statistical frequency ranking: the 2023 edition had no public data contributions and was assembled from specialist review and community feedback. OWASP’s release announcement states, “Authorization remains the biggest challenge in API Security,” noting that three of the top five categories concern authorization.

What API security protects

An API exposes functions and data that other software can call. A secure design answers four questions for every request:

  • Who is calling? Authentication establishes an identity or workload.
  • What may that caller do? Authorization evaluates roles, scopes, ownership, and policy.
  • What may the request consume or reach? Limits, validation, and egress controls constrain abuse.
  • What happens when dependencies respond? Data from partner APIs is treated as untrusted input.

Security must be enforced in the API service itself, not only in a browser, mobile client, gateway, or documentation. Attackers can call endpoints directly and can alter every client-side value.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Authentication versus authorization

Concern Question answered Typical controls
Authentication Who is this principal? Credential verification, token signature and expiry validation, issuer and audience checks, refresh-token protection, and key rotation
Authorization May this principal perform this action on this resource and field? Object-ownership checks, scopes, roles, policy decisions, and deny-by-default rules

A valid token proves only that a credential was accepted. It does not prove that the caller may read invoice 1842, change an account’s email address, or invoke an administrative operation. Perform authorization after authentication and before every sensitive read or write.

The OWASP API Security Top 10 (2023)

The categories below are the current OWASP API Security Top 10. Use them as a threat-modeling and review checklist rather than as a claim that the first item is always the most common in your environment.

Category What fails Defensive focus
API1: Broken Object Level Authorization A request-supplied identifier lets one user access another user’s object. Authorize every object lookup for the requesting principal; never rely on an opaque or unpredictable ID.
API2: Broken Authentication Weak or incorrectly implemented authentication lets an attacker compromise a token or assume another identity. Use a well-tested identity flow; validate token signature, issuer, audience, expiry, and required claims; protect credentials and recovery paths.
API3: Broken Object Property Level Authorization Responses expose fields a caller should not see, or clients can modify protected fields through mass assignment. Define response and writable-field allowlists for each role and operation. Do not serialize database objects wholesale.
API4: Unrestricted Resource Consumption Large, expensive, or high-volume requests exhaust money, CPU, memory, connections, or downstream quotas. Apply authenticated quotas, rate limits, request and upload-size limits, pagination ceilings, timeouts, concurrency limits, and monitoring.
API5: Broken Function Level Authorization A low-privilege user reaches an administrative or otherwise restricted function. Check privilege for every operation, including undocumented, internal, and alternate HTTP-method routes.
API6: Unrestricted Access to Sensitive Business Flows Automation abuses a legitimate workflow such as scalping, bulk signup, or repeated promotion claims. Map high-value workflows and add appropriate throttling, quotas, friction, anomaly detection, and state-transition checks.
API7: Server-Side Request Forgery User-controlled destinations make the server fetch an unintended resource. Use an allowlist of schemes, hosts, ports, and paths; resolve and validate addresses; restrict egress and re-check redirects.
API8: Security Misconfiguration Unsafe defaults, debug output, inconsistent environments, or overly permissive cross-origin and transport settings expose the service. Harden production configuration, remove debug routes and secrets from errors, enforce TLS, and review configuration drift.
API9: Improper Inventory Management Forgotten hosts, old versions, debug endpoints, or undocumented routes remain exposed. Maintain an owner, purpose, data classification, authentication method, and retirement date for every host, endpoint, and version.
API10: Unsafe Consumption of APIs Developers trust a partner response more than user input and process malicious or unexpected data. Validate schemas, size, type, encoding, and business rules for every external response; isolate failures and log the dependency.

Make authorization explicit and testable

Prevent broken object-level authorization

Any endpoint that accepts an ID, username, filename, or other object key needs an ownership or policy decision in the same request path. Querying an object by ID and returning it is not authorization. Scope the query to the principal, or fetch it and reject unless a policy check succeeds.

// Illustrative Express-style handler
app.get('/accounts/:accountId/invoices/:invoiceId', requireUser, async (req, res) => {
const invoice = await db.invoice.findUnique({ where: { id: req.params.invoiceId } });
if (!invoice) return res.sendStatus(404);
const allowed = await policy.canReadInvoice(req.user, invoice);
if (!allowed) return res.sendStatus(403);
res.json({ id: invoice.id, total: invoice.total, dueDate: invoice.dueDate });
});

Do not turn a 404 into a way to bypass authorization: choose a consistent policy for resource-existence disclosure and apply it across endpoints. Add tests that replay the same request with a second user, a second tenant, and an administrator.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Control properties, not only objects

Use separate output schemas and input schemas. A profile response may include a display name but not recovery factors or internal risk flags. An update endpoint should accept only fields that the caller can change; ignore or reject fields such as ownerId, role, balance, or approval state unless a separate privileged operation authorizes them.

Protect functions and state transitions

Require an explicit permission for each operation, not merely for a URL prefix. Check HTTP method variants, bulk endpoints, GraphQL resolvers, background jobs, and “internal” routes that are reachable from a shared network. For sensitive workflows, enforce valid state transitions server-side; a client must not be able to jump from draft to paid by changing a field.

Layered API security practices

Authenticate and validate tokens correctly

  • Require TLS for credentials and tokens in transit.
  • Validate signature, issuer, audience, expiry, not-before, and required scopes or claims; reject unexpected algorithms and malformed tokens.
  • Keep access tokens short-lived where practical, protect refresh tokens, and provide revocation or rotation for suspected compromise.
  • Separate human, service, and machine identities so a leaked integration credential has the narrowest possible authority.

Limit resource use and business-flow abuse

Rate limiting alone is not a complete control. Combine per-principal and per-IP limits with quotas, body and file-size ceilings, pagination limits, concurrency controls, timeouts, and downstream budgets. Return a predictable 429 response and instrument rejected requests. For signup, checkout, reservation, password-reset, and similar flows, measure actions per account and device as well as raw requests; otherwise an attacker can rotate IP addresses.

Validate input and outbound destinations

Parse against an explicit schema, reject unknown fields when appropriate, constrain lengths and numeric ranges, and canonicalize before validation. For server-side fetch features, allow only required schemes and destinations, block private and link-local address ranges, restrict DNS resolution and redirects, and apply short connect and read timeouts. Network controls are a backstop; the application must still validate the requested destination.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Harden configuration and errors

Disable debug and stack traces in production, remove default credentials, keep CORS and cookie settings narrowly scoped, and store secrets outside source code. Return an error identifier rather than database details, tokens, SQL, or internal hostnames. Keep security settings consistent across staging and production, while ensuring test environments cannot reach production data.

Rank #4
API Security in Action
  • API Security in Action
  • Manning Publications
  • ABIS BOOK

Inventory every API

Maintain a machine-readable inventory of hosts, routes, versions, owners, data sensitivity, authentication requirements, and deprecation dates. Reconcile it with gateway logs, DNS, deployment manifests, and cloud load balancers. Version retirement is a security control: an old route often lacks current authorization and validation fixes.

Treat third-party responses as untrusted

Validate status codes, content type, schema, size, encoding, and business meaning. Set timeouts and circuit breakers, isolate dependency failures, and avoid passing partner-provided HTML, URLs, or commands into privileged interpreters. Log the dependency and a correlation ID without recording secrets or unnecessary personal data.

A practical implementation sequence

  1. Map the attack surface. List hosts, versions, routes, methods, data stores, queues, and outbound integrations. Assign an owner and data classification.
  2. Write authorization decisions first. For every operation, document the principal, tenant, object, fields, allowed transitions, and denial behavior.
  3. Centralize authentication validation. Use one reviewed middleware or library, but keep resource and function authorization in the service that owns the data.
  4. Add abuse budgets. Set request, body, upload, pagination, concurrency, and workflow limits based on business cost and downstream capacity.
  5. Harden ingress and egress. Enforce TLS, schema validation, safe errors, SSRF destination policy, and outbound timeouts.
  6. Test negative paths. Include cross-user and cross-tenant object IDs, hidden fields, method changes, expired tokens, oversized bodies, replayed workflow steps, and malicious dependency responses.
  7. Monitor and rehearse. Record authentication failures, authorization denials, limit violations, unusual workflow rates, dependency errors, and configuration changes. Alert on patterns and document response actions.

Performance, reliability, and cost trade-offs

Authorization checks add database or policy-service work. Keep decisions close to the data owner, index tenant and owner keys, cache only decisions with a defined lifetime, and invalidate caches when roles or ownership change. Rate limits require counters and storage; choose a bounded window or token-bucket design that matches the abuse you need to stop. Tight limits improve resilience but can block legitimate batch jobs, so publish quotas and provide an authenticated increase path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inventory, logging, and schema validation also consume storage and processing time. Sample high-volume success events while retaining security-relevant denials and administrative changes. Never trade away object-level checks or token validation for latency; optimize their implementation instead.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common failures

Symptom Likely cause Fix
Every request returns 401 Signature key, issuer, audience, clock, or Authorization-header parsing mismatch Inspect the token claims and server clock in a safe diagnostic context; verify the expected scheme and key set, then remove verbose diagnostics.
A user can read another tenant’s record Lookup uses only a supplied ID Scope the query by tenant or perform an explicit ownership policy check; add a cross-tenant regression test.
Hidden fields appear in JSON Database object is serialized directly Map to an allowlisted response schema and add role-specific field tests.
Legitimate clients receive 429 One global or IP-only limit ignores principals, bursts, or trusted jobs Use separate budgets for identities and operations, document limits, and monitor rejected-versus-successful work.
URL-fetch endpoint reaches internal services Only the URL syntax was validated Implement destination allowlisting, private-address blocking, redirect revalidation, egress filtering, and timeouts.
Old endpoints keep appearing Inventory is maintained manually Reconcile deployment, gateway, DNS, and log sources; assign owners and retirement dates.
Partner outage causes cascading failures No timeout, size limit, circuit breaker, or schema validation Bound every call, validate responses, fail closed for sensitive actions, and degrade with a safe, explicit result.

Or skip the browser setup

If you need clean screenshots of API documentation, dashboards, or test results for a security review, ScreenshotNeo provides a single-call website screenshot API. Before capture it accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and each response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server lets Claude, Cursor, and other MCP clients use take_screenshot, get_page_info, and capture_pdf.

Example request (see the ScreenshotNeo documentation):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The service includes full-page and element capture, device and viewport controls, retina scale, PDF output, custom CSS and JavaScript, waits, request blocking, headers, cookies, user agents, authorization, timezone and geolocation, caching, signed links, asynchronous webhooks, bulk capture, usage data, and an OpenAPI specification. Every feature is available on every plan. The free plan includes 1,000 screenshots each month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Is the 2023 OWASP list a compliance standard?

No. It is an awareness and review framework. Map its categories to your own threat model, regulatory obligations, architecture, and incident history.

Should internal APIs skip authorization checks?

No. Internal networks and service identities can be compromised or misconfigured. Enforce least privilege and object, property, and function checks at the service that owns the data.

What should an API security test always include?

At minimum, test cross-user and cross-tenant object access, protected-field reads and writes, privileged-function calls, expired or altered tokens, resource-limit behavior, SSRF destinations, deprecated routes, and malformed third-party responses.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.