# Top 12 Tips for API Security

---

* Use HTTPS
    
* Use OAuth2
    
* Use WebAuthn
    
* Use Leveled API Keys
    
* Authorization
    
* Rate Limiting
    
* API Versioning
    
* Whitelisting
    
* Check OWASP API Security Risks
    
* Use API Gateway
    
* Error Handling
    
* Input Validation
    

---

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1703932976791/88902e92-7ca5-40fc-b9f5-3659aa12afd9.jpeg align="center")
