6 Comments
User's avatar
Raul Junco's avatar

Great article, Saurabh. It’s spot on with API security basics!

I cannot emphasize enough setting rate-limiting mechanisms, even for private APIs.

I learned a hard lesson when an internal consumer scanned my API to build a cache.

Thanks for the shoutout.

Saurabh Dashora's avatar

Haha...that's a pretty alarming scenario. You never know how the consumer might use your API. It's better to secure the API proactively.

Thanks Raul!

Fran Soto's avatar

It's interesting how some of these may have been a "nice to have" in the past but I consider them a must right now. That shows technology is more robust right now!

Thanks for sharing my article, Saurabh πŸ™‡

Saurabh Dashora's avatar

Thanks Fran. And you are right...many of these strategies have become a must have these days.

Petar Ivanov's avatar

These are six must-to-have features of a robust API. Security matters!

Thanks for the shoutout!

Akos Komuves's avatar

Great article Saurabh! I'm curious: what's your take on security through obscurity?