API security covers practices and technical controls that protect application programming interfaces from abuse, data leakage and unauthorized access. Core aspects include authentication, authorization, input validation, encryption and monitoring. Clear policies and observability reduce attack surface and help ensure integrity, confidentiality and availabili…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
API security protects application programming interfaces from unauthorized access, manipulation, and data leakage by securing identity, permissions, inputs, transport, and observability together.
API security became important as APIs turned into durable integration points for mobile, SaaS, partner, and internal systems while exposing business logic and sensitive data. Recurring patterns such as broken authorization, weak authentication, and excessive data exposure created a need for shared guidance. The OWASP API Security Project, launched in 2019, consolidated these risks for practice.
Think of API security as a layered control chain: first verify who is calling. Then ask whether that identity may perform the specific action on the specific object. Next inspect inputs, response data, and logs for abuse. Finally, monitoring and alerts surface unusual patterns. A gateway can centralize parts of this, but it does not replace enforcement in the backend.
A service verifies who or what is making a request.
After identity is verified, the system decides which resources and actions are allowed.
Inputs are checked for structure, type, size, and unexpected content before processing.
Data is protected from eavesdropping and tampering while it travels between parties.
Logs, metrics, and alerts make suspicious patterns, errors, and attack attempts visible.
A central layer can bundle checks, protection, and routing, but it does not replace backend enforcement.
This topic matters for public APIs, partner integrations, microservices, procurement, and security reviews. It becomes especially important when personal, financial, or control data is exposed. A gateway alone is not enough; missing object checks, sloppy error handling, and overly broad permissions remain risks. Stronger controls often also increase effort, latency, and integration complexity.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.