API Security, Authentication and Authorization Questions

Controlling who can call an API, what they may do, and defending it against abuse. Covers the access-control mechanics: API keys, OAuth 2.0 flows, OpenID Connect, JWT issuance/validation, session vs. token auth, scopes/roles for fine-grained authorization, token lifetime and refresh, mutual TLS, and machine-to-machine vs. user-delegated access. Also covers the adversarial hardening view: input validation, injection and deserialization risks, broken object-level authorization (BOLA), mass assignment, secrets handling, and the OWASP API Security Top 10, plus securing data in transit, preventing enumeration/scraping, and testing APIs for vulnerabilities.

MediumTechnical
51 practiced

You're building a secure webhook receiver for third-party partners. Requirements: authenticate payloads, prevent replay attacks, support retries while ensuring idempotency, scale to high volume, and allow secret rotation. Describe signing schemes (HMAC vs asymmetric), replay defenses (timestamps, unique IDs), idempotency handling and operational patterns for secret rotation.

HardTechnical
61 practiced

How would you handle authentication token lifecycle and rotation for long-lived API clients such as IoT devices? Include token issuance, refresh, rotation, revocation, offline device handling, heartbeat strategies, secure storage on device, and methods for detecting and responding to token compromise.

HardSystem Design
60 practiced

Lay out the API contract and operational controls for partner integrations that will process PII and PCI data. Cover authentication (mutual TLS, OAuth), token lifecycle management, field-level encryption, throttling and quota models, audit trails and logging, data retention and deletion policies, and how you'd demonstrate compliance during pre-sales and onboarding.

MediumTechnical
58 practiced

Build an automated test to detect timing side-channel leaks in an authentication API where the response time might differ based on username validity. Explain how you would reduce noise, choose sample sizes, apply statistical analysis, and automate detection in CI without producing many false positives due to network variance.

HardTechnical
69 practiced

Propose detection and mitigation strategies for abusive API usage and credential theft at scale. Cover techniques such as per-key behavioral baselines, anomaly detection, per-key throttling and freezing, ephemeral credential issuance, credential rotation, fingerprinting, and forensics-ready logging while balancing privacy and performance.

Unlock Full Question Bank

Get access to all API Security, Authentication and Authorization interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.