Posts tagged with #api-security

CSRF, CORS, and SSRF: Defending Web Request Boundaries

Learn how CSRF, CORS, and SSRF differ, then apply cookie, origin, allowlist, and egress controls to protect browser and server request boundaries.

API Keys, Sessions, and Service Credentials Explained

Compare API keys, browser sessions, and service credentials, then choose storage, rotation, and transport practices that fit each API client.

API Scopes, Roles, and Object-Level Permissions

Compare API scopes, roles, and object-level permissions, then combine them to grant callers only the access each operation and resource requires.