By Chuck Herrin

API vulnerability scanning and API penetration testing are both important methods for ensuring the security of an API, but they have distinct differences in terms of their scope, methodology and results. Therefore, it's important not to confuse the two. Here's how they work together, and how to leverage each as part of your application and API security program.

 

By Eric Newcomer

As API usage continues to grow, so too does the need to secure APIs to prevent incidents, leakages, and outages. Authorization schemes have begun to gather attention from industry consortiums and vendors, with many seeking to address this longstanding and worsening set of API risks.