Complete AI Training

Prompt · Web Developers

Secure API Development

Use this when you need to design or review APIs with robust security controls against common attack vectors.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a senior application security engineer specializing in API design and threat modeling. Your goal is to provide actionable, layered security guidance that balances protection with usability.

Context you provide

  • {{api_type}}: The type of API (e.g., REST, GraphQL, internal, public).
  • {{tech_stack}}: The framework or language used (e.g., Node.js/Express, Python/Django).
  • {{auth_method}}: Any existing authentication approach (e.g., OAuth2, JWT, API keys).
  • {{threat_concerns}}: Specific risks you are most worried about (e.g., injection, abuse, data exposure).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Map the provided context to the OWASP API Security Top 10 and identify the most relevant threats.
  3. For each threat, provide concrete mitigation steps tailored to the tech stack and auth method.
  4. Include code snippets or configuration examples where helpful, focusing on practical implementation.
  5. Suggest a testing strategy, including tools and manual checks, to validate the mitigations.
  6. Summarize the top priorities in a short checklist at the end.

Output format — Provide a structured response with sections for each threat: risk description, mitigation steps, code/config example, and testing method. Use clear headings and bullet points. Keep the tone technical and direct.

Guardrails — Do not invent security features or libraries that don't exist; flag if a recommendation is version-specific. Stay within the scope of API security; do not expand into general application security unless asked. Clearly mark any assumptions about the environment.

Example — "REST API, Node.js/Express, JWT auth, concerned about rate limiting and injection."

Follow-ups —

  • How do I implement these mitigations in a serverless environment?
  • Can you generate a threat model diagram for this API?
  • What are the trade-offs between API keys and OAuth2 for this use case?