API Security Guideline for Developers and Product Owners

2025-1-10
Akgündüz, Okan
This report provides a survey for security topics, practices, and recommendations to consider when designing, developing, and maintaining an API service. It is primarily intended for developers, product owners, and other stakeholders involved in API development. Additionally, it is relevant to those who consume API services. The report draws from widely recognized security standards, guidelines, and surveys. It is created by examining the most common API security vulnerabilities identified in existing studies. Its scope of work is then expanded to include potential vulnerabilities that can arise during an API service’s development process/lifecycle. For each identified vulnerability/risk/issue, the report outlines recommended mitigations based on standards and guidelines. The result is a categorized list that can be used as an API Security Guideline.
Citation Formats
O. Akgündüz, “API Security Guideline for Developers and Product Owners,” M.S. - Master Of Science Without Thesis, Middle East Technical University, 2025.