API Security, Authentication and Authorization Questions

Controlling who can call an API, what they may do, and defending it against abuse. Covers the access-control mechanics: API keys, OAuth 2.0 flows, OpenID Connect, JWT issuance/validation, session vs. token auth, scopes/roles for fine-grained authorization, token lifetime and refresh, mutual TLS, and machine-to-machine vs. user-delegated access. Also covers the adversarial hardening view: input validation, injection and deserialization risks, broken object-level authorization (BOLA), mass assignment, secrets handling, and the OWASP API Security Top 10, plus securing data in transit, preventing enumeration/scraping, and testing APIs for vulnerabilities.

EasyTechnical
69 practiced

Explain the difference between authentication and authorization in the API context. Describe two common authentication methods (JWT bearer tokens and OAuth2 Authorization Code flow) and two authorization models (role-based access control RBAC and attribute-based access control ABAC). For each, give a short example of when it is appropriate.

MediumTechnical
51 practiced

You're building a secure webhook receiver for third-party partners. Requirements: authenticate payloads, prevent replay attacks, support retries while ensuring idempotency, scale to high volume, and allow secret rotation. Describe signing schemes (HMAC vs asymmetric), replay defenses (timestamps, unique IDs), idempotency handling and operational patterns for secret rotation.

EasyTechnical
48 practiced

Compare API keys, JSON Web Tokens (JWTs), and OAuth 2.0 access tokens: describe typical use cases, security properties (revocation, statelessness, signature verification), storage considerations, and common attack vectors (theft, replay, misuse). When would you choose each approach in a modern API platform?

EasyTechnical
55 practiced

Explain the differences between input validation, schema/contract validation (OpenAPI/JSON Schema), and output encoding. Give concrete examples of how each prevents different attack classes such as SQL injection, XSS, and parameter pollution, and list common developer mistakes that lead to validation bypasses.

MediumTechnical
63 practiced

Explain how to use JSON Schema and OpenAPI validation to mitigate parameter pollution, type confusion, and injection attacks. Provide concrete schema constraints (pattern, enum, maxLength, additionalProperties:false) and explain where contract validation should run (gateway vs service) and how to handle legitimate unknown fields gracefully.

Unlock Full Question Bank

Get access to all 20 API Security, Authentication and Authorization interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.