API Security, Authentication and Authorization Questions

Controlling who can call an API, what they may do, and defending it against abuse. Covers the access-control mechanics: API keys, OAuth 2.0 flows, OpenID Connect, JWT issuance/validation, session vs. token auth, scopes/roles for fine-grained authorization, token lifetime and refresh, mutual TLS, and machine-to-machine vs. user-delegated access. Also covers the adversarial hardening view: input validation, injection and deserialization risks, broken object-level authorization (BOLA), mass assignment, secrets handling, and the OWASP API Security Top 10, plus securing data in transit, preventing enumeration/scraping, and testing APIs for vulnerabilities.

HardTechnical
96 practiced

Compare opaque tokens versus self-contained JWTs for service-to-service authentication in a distributed microservices environment. Discuss performance (validation latency), revocation complexity, payload confidentiality, token size, caching implications, and give recommendations for hybrid approaches that balance stateless validation with revocation needs.

HardTechnical
57 practiced

Perform a threat model for an external-facing API. Identify threats such as injection attacks, broken authentication, excessive data exposure, rate-limiting bypass, and DDoS. As a Solutions Architect, propose mitigation strategies including validation, least-privilege, rate limits, WAF, and API-level quotas, and discuss trade-offs and monitoring approaches.

HardSystem Design
70 practiced

You need an access control model for an API that supports fine-grained permissions (resource-level, action-level) and can scale to millions of principals and resources. Discuss evaluation latency, caching of permissions, hierarchical roles, attribute-based access control, and how to keep revocation latency low.

MediumSystem Design
65 practiced

Build an authentication and authorization scheme for a multi-tenant API that supports bearer tokens for user auth and API keys for service-to-service calls. Include per-tenant rate limits, key rotation, revocation, secure key storage, and how to represent tenant scoping in tokens or claims.

HardSystem Design
58 practiced

Architect a security model for a large-scale microservices platform (~1000 services) that uses a service mesh (e.g., Envoy/Istio) and an API gateway. Goals: enforce strong service-to-service authentication and authorization, minimize blast radius, centralize policy where sensible but avoid bottlenecks, ensure observability and incident response. Provide key components, identity model, policy enforcement points, rollout plan and scaling considerations.

Unlock Full Question Bank

Get access to all 25 API Security, Authentication and Authorization interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.