API Security Design

Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API Security Top 10 and Azure API Management. WHEN: API security design, secure API, OWASP API Top 10, API authentication, API gateway security, rate limiting, validate JWT, protect backend API, API Management security policies, secure API architecture, BOLA, BFLA. DO NOT USE for general application security or web app design (use security-architecture / threat-modelling) or for API runtime detection only (use defender-for-apis).

vinayaklatthe 1a5f228 8.7 KB Updated

File contents

vinayaklatthe/microsoft-security-skills/tree/main/skills/api-security-design commit 1a5f228e39

Frequently asked questions

npx skillmds@latest add vinayaklatthe/api-security-design