6 Comments

Great article, Saurabh. It’s spot on with API security basics!

I cannot emphasize enough setting rate-limiting mechanisms, even for private APIs.

I learned a hard lesson when an internal consumer scanned my API to build a cache.

Thanks for the shoutout.

Expand full comment

Haha...that's a pretty alarming scenario. You never know how the consumer might use your API. It's better to secure the API proactively.

Thanks Raul!

Expand full comment

It's interesting how some of these may have been a "nice to have" in the past but I consider them a must right now. That shows technology is more robust right now!

Thanks for sharing my article, Saurabh 🙇

Expand full comment

Thanks Fran. And you are right...many of these strategies have become a must have these days.

Expand full comment

These are six must-to-have features of a robust API. Security matters!

Thanks for the shoutout!

Expand full comment

Great article Saurabh! I'm curious: what's your take on security through obscurity?

Expand full comment