WeAreDevelopers LIVE Apr 29, 2022

Architecting API Security

Philippe De Ryck

An attacker breaches your API gateway and suddenly gains unchecked access across your trusted network. Prevent catastrophic lateral movement by shifting from perimeter defenses to a zero-trust architecture.

Pause
Mute Enter Fullscreen
#1 about 4 min

Designing APIs for security from day one

Prioritizing early architectural design prevents critical authorization and authentication flaws commonly found in real-world application deployments.

#2 about 3 min

Establishing a baseline modern API architecture

A typical modern infrastructure utilizes reverse proxies and API gateways to route authorized traffic to monolithic or microservice components.

#3 about 9 min

How internal vulnerabilities breach perimeter security

Exploiting standard processes like image conversion demonstrates why relying solely on perimeter defenses leaves internal trusted zones entirely defenseless against remote code execution.

#4 about 6 min

Containing lateral threats with service compartmentalization

Isolating untrusted or highly sensitive services into distinct trust zones mitigates widespread infrastructure compromise when targeted individual components fail.

#5 about 5 min

Enforcing zero trust policies with inter-API authentication

Implementing strict caller verification and explicit communication paths stops compromised internal services from arbitrarily traversing the backend network.

#6 about 6 min

Forwarding authentication state via token relay

Relaying identity contexts past the external gateway empowers internal microservices to execute precise object-level authorization decisions for individual users.

#7 about 3 min

Security drawbacks of exposing JWTs to clients

Delivering raw JSON web tokens to frontend clients incurs large network overheads, complicates session revocation, and risks leaking sensitive backend claim data.

#8 about 4 min

Obfuscating JWTs with API gateway reference tokens

Gateways can maintain server-side token state and issue opaque reference identifiers to clients to obscure internal authorization topologies and simplify session invalidation.

#9 about 2 min

Key architectural takeaways for building secure APIs

Assuming breach necessitates prioritizing simple, compartmentalized architectural solutions that leverage edge gateways to shield internal implementation complexities.

#10 about 10 min

Audience Q&A on fine-grained access and JWT encryption

Addressing inquiries regarding career paths, configuring fine-grained access with open policy agents, and the challenges of managing keys for token encryption.

Matching moments

6:44 min

Designing a resilient API gateway architecture

Lars Hesel Christensen +1 · LIVE

3:15 min

The current state of enterprise APIs and security trends

Pratim Bhosale Pratim Bhosale · WWC 2025

9:56 min

Final code walk-through and audience Q&A session

Germán Álvarez · LIVE

1:36 min

Securing exposed application programming interfaces against unauthenticated access

Jasmin Azemović Jasmin Azemović · WWC 2023

2:31 min

Addressing insecure design through early threat modeling

Christian Wenz Christian Wenz · WWC Europe 2026

3:45 min

Applying zero trust architecture to backend microservices

Jan Peer Stöcklmair Jan Peer Stöcklmair · WWC Europe 2026

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Designing APIs That Survive AI Agents at Scale

Phani Pendurthi

Mastercard, Principal Software Engineer

Phani Pendurthi
Open session

World Congress 2026 North America

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash
Open session

World Congress 2026 North America

Zero-Trust Architecture for Agentic AI: Securing Multi-User Access and Third-Party Integrations

Borko Djurkovic

Member of Technical Staff at Cohere

Borko Djurkovic
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

API = Some REST and HTTP, right? RIGHT?!

Rustam Mehmandarov

Passionate computer scientist

Rustam Mehmandarov