Mastodon Mastodon Mastodon Mastodon

Application Programming Interface [API]

Updated: · CyberSecureFox Editorial Team

An application programming interface (API) is a defined set of rules that lets one program request data or functions from another.

How an API works

An API describes which requests a program may send, in what format, and what it gets back. A weather app, for example, sends an HTTP request to a weather service’s API and receives JSON data with the forecast. Common styles are:

  • REST – resources addressed by URLs and HTTP methods (GET, POST, PUT, DELETE);
  • GraphQL – the client asks for exactly the fields it needs;
  • gRPC and other binary protocols for fast service-to-service communication;
  • local APIs of operating systems and libraries, such as the Windows API.

Modern web and mobile apps, cloud services and AI models are built almost entirely on APIs.

Why APIs matter for security

APIs expose business logic and data directly, often without the protection a web interface has. The OWASP API Security Top 10 (2023) lists the most frequent flaws; number one is broken object level authorization (BOLA): changing an ID in a request returns another customer’s data. Other typical problems are weak authentication, excessive data in responses, missing rate limits and forgotten “shadow” API versions. Leaked API keys in public code repositories are a constant source of breaches.

Best practices

  • Check authorization for every object on the server side, not only at login.
  • Use standard authentication (OAuth 2.0, short-lived tokens) and keep API keys in a secrets manager.
  • Apply rate limiting, input validation and an up-to-date API inventory.
  • Scan repositories for leaked secrets and rotate keys immediately if exposed.