Guidance
Securing HTTP-based APIs
How to ensure that application programming interfaces are designed and built securely.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 1 of 8

This guidance provides advice on securing HTTP-based APIs. It is aimed at technical members of staff who are responsible for designing or building applications that offer an HTTP API. Note that you should conduct threat modelling tailored to your specific design to completely secure your HTTP-based APIs.
HTTP-based APIs enable communication between different software systems, often including third-party services, and can be used to access services and databases, manipulate data, or even handle user authentication and authorisation. They are a key component in the architecture of modern internet applications.
An API (application programming interface) is typically defined as a set of specifications (such as the format of HTTP requests sent to API endpoints) along with a definition of the structure of response messages, usually in JSON format. APIs can be used to receive some data, upload some data or control an action or system.
Attackers can exploit weaknesses and vulnerabilities in APIs in a number of ways. For example, they could:
As HTTP-based APIs are shared outside of your organisation with the intent of making data or capability available, you should perform service-specific threat modelling to understand the relevant risks and threats.


