12 Tips For API Security Use HTTPS Use OAuth2 Use WebAuthn Use Leveled API Keys Authorization Rate Limiting API Versioning Allow list Check OWASP API Security Risk Use API Gateway Error Handling Input Validation