Skip to main content
Guidance

Securing HTTP-based APIs

How to ensure that application programming interfaces are designed and built securely.

Page 3 of 8

2. API authentication and authorisation

Implementing robust authentication and authorisation is critical for securing an API, ensuring that only legitimate users or services can access endpoints and perform actions. Authentication verifies the identity of the entity making an API request, while authorisation controls what actions the authenticated entity is allowed to perform.

In many cases, authentication and authorisation are closely linked, with certain mechanisms serving both functions. For instance, tokens issued by an identity provider can authenticate a user and contain claims that define what the user is authorised to do.

Choosing the correct authentication and authorisation methods requires careful planning and consideration of the specific needs of the application.





Published

Reviewed

Version

1.0