API security

API Security Articles

What this covers

These posts cover API security testing and design: authorisation enforced per object rather than per screen, token lifetime and revocation, mass assignment, rate limiting on the endpoints that matter, and keeping an inventory of what is actually routable.

An API does not know what the client renders. Every control that matters has to be enforced server side, per request, per object — and the findings below are what happens when that assumption slips, one endpoint at a time.

3 posts in API security.

Want this tested properly?

Scope and a fixed quote within two working days. First consultation is free.