Application Security

API Security: Mistakes We See Again and Again

September 2026 · 4 min read

APIs now carry most of the traffic and most of the sensitive data in modern applications, and they are tested less thoroughly than the interfaces built on top of them. A handful of mistakes account for many of the issues we see.

The most common is broken object-level authorisation. An API checks that you are logged in but not that the record you request belongs to you, so changing an identifier in the request exposes someone else's data.

Next is excessive data exposure. Endpoints return whole objects and rely on the front end to hide fields, which means everything is visible to anyone reading the response.

Weak authentication handling comes up often too: tokens that never expire, long-lived keys shared between environments and JSON web tokens accepted without proper validation.

Missing rate limits allow credential stuffing, scraping and resource exhaustion. Limits should apply per user and per key, not only per address.

Old versions and forgotten endpoints are easy to overlook. Documentation, staging endpoints and deprecated versions often remain reachable without the protections added to the current version.

Maintain an inventory of every endpoint, enforce authorisation on the server for every request and test the API directly, not only through the application that uses it.

Want Help With This?

If this touched on something you are dealing with right now, we are happy to talk it through.

More Reading

Related Articles