API Security, Authentication and Authorization Questions

Controlling who can call an API, what they may do, and defending it against abuse. Covers the access-control mechanics: API keys, OAuth 2.0 flows, OpenID Connect, JWT issuance/validation, session vs. token auth, scopes/roles for fine-grained authorization, token lifetime and refresh, mutual TLS, and machine-to-machine vs. user-delegated access. Also covers the adversarial hardening view: input validation, injection and deserialization risks, broken object-level authorization (BOLA), mass assignment, secrets handling, and the OWASP API Security Top 10, plus securing data in transit, preventing enumeration/scraping, and testing APIs for vulnerabilities.

HardSystem Design
68 practiced

Propose a policy-as-code solution (for example using Open Policy Agent - OPA) to enforce attribute-based access control across APIs. Describe where policies should evaluate (sidecar, gateway, service), policy distribution/versioning, performance strategies (caching/compile-time optimizations), CI testing of policies, and how to secure attribute sources and mitigate stale attributes.

HardSystem Design
56 practiced

Design an audit logging and telemetry schema for APIs to support security investigations and compliance (e.g., GDPR, SOC2). Specify required log fields (principal, action, resource, timestamp, request/response metadata, trace-id), redaction rules, retention policies, storage backends, indexing strategies, sampling, and how to balance forensic needs with cost and privacy.

HardTechnical
60 practiced

You must securely integrate several third-party APIs into your platform. Describe a secure integration strategy covering vendor vetting, credential management (per-tenant credentials, rotation), sandboxing/testing, rate-limiting and circuit-breakers, monitoring for anomalous behavior, contractual SLAs and how to mitigate supply chain risks from third-party compromises.

MediumSystem Design
95 practiced

Build a secure, auditable data-sharing API for content partners (studios) to receive usage reports and aggregated metrics. Define authentication, authorization, data transformations/aggregation to protect PII and trade secrets, rate limits, schema versioning, and logging/auditing for access and changes.

EasyTechnical
53 practiced

Walk me through mutual TLS (mTLS): how does the handshake differ from standard one-way TLS, how do the client and server present and verify each other's certificates, and what are the practical options for certificate provisioning and rotation for service-to-service authentication in a microservice or service-mesh deployment?

Unlock Full Question Bank

Get access to all API Security, Authentication and Authorization interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.