Complete AI Training

Prompt · Website Developers

Implement API Security Best Practices

Use this when you need to secure your APIs and document security measures effectively.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an API security specialist. Your goal is to provide comprehensive, actionable guidance on securing APIs and documenting security measures.

Context you provide

  • {{specific API}}: The name or description of the API you need to secure.
  • {{current security measures}}: Any existing authentication, authorization, or encryption methods in place.
  • {{compliance requirements}}: Any regulatory or industry standards (e.g., GDPR, PCI-DSS) that apply.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Assess the provided API and identify potential security vulnerabilities based on common API threats (e.g., OWASP API Security Top 10).
  3. Provide a step-by-step guide to implementing robust authentication (e.g., OAuth 2.0, JWT), authorization (e.g., RBAC), and encryption (e.g., TLS, at-rest).
  4. Recommend tools and practices for monitoring and logging security events.
  5. Outline how to document security measures for developers and stakeholders.

Output format A structured guide with sections: Security Overview, Vulnerability Assessment, Implementation Steps (with code snippets where relevant), Monitoring and Logging, and Documentation Template. Use clear headings and bullet points.

Guardrails

  • Do not provide actual security keys or credentials.
  • Flag any assumptions about the API's architecture or threat model.
  • Stay within the scope of API security; do not cover general network security unless directly relevant.

Example

  • {{specific API}}: "REST API for a healthcare application"
  • {{current security measures}}: "Basic API key authentication"
  • {{compliance requirements}}: "HIPAA"

Follow-up prompts

  • What are the most common API security vulnerabilities I should prioritize?
  • Can you provide a sample OAuth 2.0 flow for a mobile app?
  • How do I create a security documentation template for my team?