API Security, Authentication and Authorization Questions

Controlling who can call an API, what they may do, and defending it against abuse. Covers the access-control mechanics: API keys, OAuth 2.0 flows, OpenID Connect, JWT issuance/validation, session vs. token auth, scopes/roles for fine-grained authorization, token lifetime and refresh, mutual TLS, and machine-to-machine vs. user-delegated access. Also covers the adversarial hardening view: input validation, injection and deserialization risks, broken object-level authorization (BOLA), mass assignment, secrets handling, and the OWASP API Security Top 10, plus securing data in transit, preventing enumeration/scraping, and testing APIs for vulnerabilities.

EasyTechnical
99 practiced

What is an API gateway, and what security responsibilities does it typically take on for the services sitting behind it?

HardSystem Design
68 practiced

Propose a policy-as-code solution (for example using Open Policy Agent - OPA) to enforce attribute-based access control across APIs. Describe where policies should evaluate (sidecar, gateway, service), policy distribution/versioning, performance strategies (caching/compile-time optimizations), CI testing of policies, and how to secure attribute sources and mitigate stale attributes.

MediumTechnical
61 practiced

Implement a thread-safe in-memory token-bucket rate limiter in Python. Provide functions:

  • set_rate(key: str, tokens_per_sec: float, burst: int)
  • acquire(key: str) -> bool

Requirements: allow bursts up to 'burst', refill at tokens_per_sec, be concurrency-safe (use threading.Lock), and avoid unbounded memory growth (evict idle keys).

HardSystem Design
55 practiced

You need an automated emergency revocation and credential rotation plan for compromised client credentials affecting thousands of clients. What would you build? Include detection triggers, mass-revocation mechanics, phased rotation, client notification strategies, fallback modes to preserve critical functionality, and automated rollback if revocations cause unintended outages.

MediumSystem Design
49 practiced

You operate a mixed monolith + microservices environment. For security controls (authentication, authorization, rate limiting, input/schema validation, transport security), decide which responsibilities should be enforced at the API gateway/proxy and which should remain inside services. Justify choices with availability, security, and performance trade-offs and propose testing and observability to validate enforcement.

Unlock Full Question Bank

Get access to all 17 API Security, Authentication and Authorization interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.