REST API Security Checklist: 12 Things to Do Before Launch
October 4, 2026 · 1 min read
Every public API gets probed within hours of going live. Work through this checklist before launch.
- Use HTTPS everywhere. Redirect HTTP, enable HSTS and monitor certificate expiry.
- Authenticate every request. Use API keys or OAuth tokens. Never put secrets in query strings because they end up in logs.
- Store secrets hashed. Keep only a hash of API keys so a database leak does not expose working credentials.
- Authorise per resource. Check that the caller owns the record on every request. Broken object level authorisation is the number one API vulnerability.
- Validate all input. Enforce types, lengths and allowed values. Reject unknown fields.
- Rate limit. Protect against brute force, scraping and accidental loops. Return
429with aRetry-Afterheader. - Limit payload size. Reject oversized bodies early with
413. - Configure CORS narrowly. Allow only the origins that need browser access.
- Return generic errors. Do not leak stack traces, SQL or internal paths.
- Log and monitor. Keep request logs, alert on spikes of 401, 403 and 5xx responses.
- Protect against SSRF. If your API fetches URLs on behalf of users, block private and internal addresses and re-check after redirects.
- Add security headers. Send
X-Content-Type-Options: nosniffand a restrictive Content-Security-Policy. Test with the HTTP header checker.
API24x7 applies these controls by default to every API you host, so you can focus on your data model.