SlideShare a Scribd company logo
© 2016 ForgeRock. All rights reserved.
Best Practices for API
Security
Ludovic Poitou, Product Management Director
© 2016 ForgeRock. All rights reserved.
API Security
?
© 2016 ForgeRock. All rights reserved.
API Security
© 2016 ForgeRock. All rights reserved.
Example:
ForgeRock
Identity Gateway
APIs
ForgeRock
Access Management
Throttling
Authorization
© 2016 ForgeRock. All rights reserved.
API Key
• Use OAuth2 Tokens
• Issued & managed centrally
• Standard based
• Access tokens are short-lived
and revocable
• Scopes for finer permissions
© 2016 ForgeRock. All rights reserved.
Protecting against Disclosure
• Secure End to End
• Between Client and Gateway
• Between Gateway and API
• TLS
• Certificate based
Authentication
© 2016 ForgeRock. All rights reserved.
Protect Against Misuse and DOS
• Throttle the incoming traffic
• Overall
• Per API
• Per Client
• Also a monetization strategy!
https://www.flickr.com/photos/telstar/
© 2016 ForgeRock. All rights reserved.
Policy Decision and Enforcement Point
• Centralized policy
management
• Introspect Token
• Call ForgeRock Access
Management PDP
• Border enforcement
• Specific rules and conditions
• Not Found vs Forbidden
https://www.flickr.com/photos/yannickgar/
© 2016 ForgeRock. All rights reserved.
Monitoring and Auditing
• Monitoring
• Status
• Throughput and Response
Times statistics
• Auditing
• Logs
• Reporting
• Billing
© 2016 ForgeRock. All rights reserved.
Summary
© 2016 ForgeRock. All rights reserved.
Throttling
Message Transformation Monitoring
Session Management Token Exchange
SSO
Scripting
Relying Party
Authentication
Authorization Federation (SAML / OIDC)
Password Capture &
Replay
Protected Resources Identity Providers Data Stores
Web Applications
APIs
Services Layer
Access Layer HTTP / HTTPS OAuth2.0 | OpenID Connect | SAMLv2
External Layer
Databases
Directories
Files
Audit
ForgeRock Identity Platform: Identity Gateway
© 2016 ForgeRock. All rights reserved. 12
© 2016 ForgeRock. All rights reserved.
Best Practices for API
Security
Ludovic Poitou – Product Management Director
Ludovic.Poitou@ForgeRock.com
@ludomp

More Related Content

PPTX
NYC Identity Summit Business Day: Continuous Security
PPTX
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
PDF
NYC Identity Summit Tech Day: Authorization for the Modern World
PPTX
NYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
PPTX
ForgeRock Gartner 2016 Security & Risk Management Summit
PDF
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
PDF
ForgeRock Platform Release - Summer 2016
PDF
Beyond username and password it's continuous authorization webinar
NYC Identity Summit Business Day: Continuous Security
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
NYC Identity Summit Tech Day: Authorization for the Modern World
NYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
ForgeRock Gartner 2016 Security & Risk Management Summit
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
ForgeRock Platform Release - Summer 2016
Beyond username and password it's continuous authorization webinar

What's hot (20)

PDF
The Future of Digital Identity in the Age of the Internet of Things
PPTX
Identity Gateway with the ForgeRock Identity Platform - So What’s New?
PDF
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
PDF
Sydney Identity Summit: Addressing the New Threat Landscape with Continuous S...
PPTX
A Backstage Tour of Identity - Paris Identity Summit 2016
PPTX
User-Managed Access: Why and How? - Access Control in Digital Contract Contexts
PDF
The Future is Now: What’s New in ForgeRock Identity Gateway
PPTX
Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades
PDF
Sydney Identity Summit: Doing Authorisation, Consent and Delegation Right wit...
PDF
Security & Identity for the Internet of Things Webinar
PDF
Identity Relationship Management - The Right Approach for a Complex Digital W...
PPT
Canberra Executive Breakfast - A Citizen-Centric Approach to Identity
PPTX
Backstage Tour of Identity - London Identity Summit
PPTX
Identity Objects in Mirror Are Closer Than They Appear - Identity Live 2017 -...
PPTX
Build a Trust Platform to Enable a Frictionless Customer Experience
PDF
Sydney Identity Unconference Introduction and Highlights
PDF
No IoT Without Identity
PDF
IoT Wonderland: Understanding the Magic of OAuth2 Device Registration Flow
PDF
The Future is Now: What’s New in ForgeRock Access Management
PPTX
Webinar: ForgeRock Identity Platform Preview (Dec 2015)
The Future of Digital Identity in the Age of the Internet of Things
Identity Gateway with the ForgeRock Identity Platform - So What’s New?
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
Sydney Identity Summit: Addressing the New Threat Landscape with Continuous S...
A Backstage Tour of Identity - Paris Identity Summit 2016
User-Managed Access: Why and How? - Access Control in Digital Contract Contexts
The Future is Now: What’s New in ForgeRock Identity Gateway
Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades
Sydney Identity Summit: Doing Authorisation, Consent and Delegation Right wit...
Security & Identity for the Internet of Things Webinar
Identity Relationship Management - The Right Approach for a Complex Digital W...
Canberra Executive Breakfast - A Citizen-Centric Approach to Identity
Backstage Tour of Identity - London Identity Summit
Identity Objects in Mirror Are Closer Than They Appear - Identity Live 2017 -...
Build a Trust Platform to Enable a Frictionless Customer Experience
Sydney Identity Unconference Introduction and Highlights
No IoT Without Identity
IoT Wonderland: Understanding the Magic of OAuth2 Device Registration Flow
The Future is Now: What’s New in ForgeRock Access Management
Webinar: ForgeRock Identity Platform Preview (Dec 2015)
Ad

Viewers also liked (14)

PDF
Uniformes empresariales, BIGBANG México
PDF
Uniformes para empresas df
PDF
13 the ciolos reform
PPT
Módulo iv slideshare
PDF
9789243503325 spa
PDF
Mexicanidad
PPT
бизнес драйв
PDF
Carta docente
PPTX
Camdenton School USA
PDF
UDES MAESTRÍA MAPA CONCEPTUAL
PPTX
High flexion TKR overview
PPSX
MGUH Joint Replacement Class
PPTX
Automobile chassis and body
Uniformes empresariales, BIGBANG México
Uniformes para empresas df
13 the ciolos reform
Módulo iv slideshare
9789243503325 spa
Mexicanidad
бизнес драйв
Carta docente
Camdenton School USA
UDES MAESTRÍA MAPA CONCEPTUAL
High flexion TKR overview
MGUH Joint Replacement Class
Automobile chassis and body
Ad

Similar to NYC Identity Summit Tech Day: Best Practices for API Security (20)

PPTX
APIs: The New Security Layer
PPTX
Adapt or Die Sydney - API Security
PDF
APIsecure 2023 - API Security - doing more with less, Nir Paz (Standard.ai)
PPTX
Deep-Dive: Secure API Management
PPTX
Rest API Security - A quick understanding of Rest API Security
PPTX
apidays LIVE Hong Kong 2021 - Digital Identity Centric Approach to Accelerate...
PPTX
apidays LIVE Hong Kong 2021 - Digital Identity Centric Approach to Accelerate...
PDF
API Security Best Practices & Guidelines
PDF
Designing Secure APIs
PPTX
London Adapt or Die: Securing your APIs the Right Way!
PDF
API Security Best Practices and Guidelines
PPTX
Deep-Dive: API Security in the Digital Age
PDF
Enhancing your Security APIs
PDF
Secure your app against DDOS, API Abuse, Hijacking, and Fraud
PDF
What is API Security and How Does It Keep Apps Safe_.pdf
PDF
5 step plan to securing your APIs
PDF
API Security Best Practices & Guidelines
PDF
42crunch-API-security-workshop
PDF
Virtual Meetup - API Security Best Practices
PDF
APIdays Paris 2019 - API Gateway & Identity Providers, a Match Made in Micros...
APIs: The New Security Layer
Adapt or Die Sydney - API Security
APIsecure 2023 - API Security - doing more with less, Nir Paz (Standard.ai)
Deep-Dive: Secure API Management
Rest API Security - A quick understanding of Rest API Security
apidays LIVE Hong Kong 2021 - Digital Identity Centric Approach to Accelerate...
apidays LIVE Hong Kong 2021 - Digital Identity Centric Approach to Accelerate...
API Security Best Practices & Guidelines
Designing Secure APIs
London Adapt or Die: Securing your APIs the Right Way!
API Security Best Practices and Guidelines
Deep-Dive: API Security in the Digital Age
Enhancing your Security APIs
Secure your app against DDOS, API Abuse, Hijacking, and Fraud
What is API Security and How Does It Keep Apps Safe_.pdf
5 step plan to securing your APIs
API Security Best Practices & Guidelines
42crunch-API-security-workshop
Virtual Meetup - API Security Best Practices
APIdays Paris 2019 - API Gateway & Identity Providers, a Match Made in Micros...

More from ForgeRock (20)

PDF
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
PPTX
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
PDF
Identity Live Sydney: Identity Management - A Strategic Opportunity
PDF
Identity Live Singapore: Transform Your Cybersecurity Capability
PDF
Identity Live Singapore 2018 Keynote Presentation
PDF
Identity Live Sydney 2018 Keynote Presentation
PDF
Identity Live Singapore: Just Ask 'Em
PDF
Identity Live Singapore: Building Trust & Privacy in a Connected Society
PDF
Identity Live Sydney: Intelligent Authentication
PDF
Identity Live Sydney: Building Trust and Privacy in a Connected Society
PDF
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
PPTX
Get the Exact Identity Solution You Need - In the Cloud - Overview
PDF
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
PDF
Opening Keynote (Identity Live Berlin 2018)
PDF
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
PDF
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
PDF
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
PDF
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
PDF
Shift from GDPR readiness to sustained compliance to improve your business an...
PDF
Intelligent Authentication (Identity Live Berlin 2018)
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Identity Live Sydney: Identity Management - A Strategic Opportunity
Identity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote Presentation
Identity Live Singapore: Just Ask 'Em
Identity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Sydney: Intelligent Authentication
Identity Live Sydney: Building Trust and Privacy in a Connected Society
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution You Need - In the Cloud - Overview
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
Opening Keynote (Identity Live Berlin 2018)
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Shift from GDPR readiness to sustained compliance to improve your business an...
Intelligent Authentication (Identity Live Berlin 2018)

Recently uploaded (20)

PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
PPTX
Odoo POS Development Services by CandidRoot Solutions
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PDF
top salesforce developer skills in 2025.pdf
PDF
System and Network Administration Chapter 2
PDF
AI in Product Development-omnex systems
PDF
PTS Company Brochure 2025 (1).pdf.......
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PPTX
history of c programming in notes for students .pptx
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PPTX
CHAPTER 2 - PM Management and IT Context
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PPTX
CHAPTER 12 - CYBER SECURITY AND FUTURE SKILLS (1) (1).pptx
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PDF
System and Network Administraation Chapter 3
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
Odoo POS Development Services by CandidRoot Solutions
Internet Downloader Manager (IDM) Crack 6.42 Build 41
Design an Analysis of Algorithms I-SECS-1021-03
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Wondershare Filmora 15 Crack With Activation Key [2025
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
top salesforce developer skills in 2025.pdf
System and Network Administration Chapter 2
AI in Product Development-omnex systems
PTS Company Brochure 2025 (1).pdf.......
VVF-Customer-Presentation2025-Ver1.9.pptx
history of c programming in notes for students .pptx
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
CHAPTER 2 - PM Management and IT Context
Design an Analysis of Algorithms II-SECS-1021-03
CHAPTER 12 - CYBER SECURITY AND FUTURE SKILLS (1) (1).pptx
How to Choose the Right IT Partner for Your Business in Malaysia
How to Migrate SBCGlobal Email to Yahoo Easily
System and Network Administraation Chapter 3

NYC Identity Summit Tech Day: Best Practices for API Security

  • 1. © 2016 ForgeRock. All rights reserved. Best Practices for API Security Ludovic Poitou, Product Management Director
  • 2. © 2016 ForgeRock. All rights reserved. API Security ?
  • 3. © 2016 ForgeRock. All rights reserved. API Security
  • 4. © 2016 ForgeRock. All rights reserved. Example: ForgeRock Identity Gateway APIs ForgeRock Access Management Throttling Authorization
  • 5. © 2016 ForgeRock. All rights reserved. API Key • Use OAuth2 Tokens • Issued & managed centrally • Standard based • Access tokens are short-lived and revocable • Scopes for finer permissions
  • 6. © 2016 ForgeRock. All rights reserved. Protecting against Disclosure • Secure End to End • Between Client and Gateway • Between Gateway and API • TLS • Certificate based Authentication
  • 7. © 2016 ForgeRock. All rights reserved. Protect Against Misuse and DOS • Throttle the incoming traffic • Overall • Per API • Per Client • Also a monetization strategy! https://www.flickr.com/photos/telstar/
  • 8. © 2016 ForgeRock. All rights reserved. Policy Decision and Enforcement Point • Centralized policy management • Introspect Token • Call ForgeRock Access Management PDP • Border enforcement • Specific rules and conditions • Not Found vs Forbidden https://www.flickr.com/photos/yannickgar/
  • 9. © 2016 ForgeRock. All rights reserved. Monitoring and Auditing • Monitoring • Status • Throughput and Response Times statistics • Auditing • Logs • Reporting • Billing
  • 10. © 2016 ForgeRock. All rights reserved. Summary
  • 11. © 2016 ForgeRock. All rights reserved. Throttling Message Transformation Monitoring Session Management Token Exchange SSO Scripting Relying Party Authentication Authorization Federation (SAML / OIDC) Password Capture & Replay Protected Resources Identity Providers Data Stores Web Applications APIs Services Layer Access Layer HTTP / HTTPS OAuth2.0 | OpenID Connect | SAMLv2 External Layer Databases Directories Files Audit ForgeRock Identity Platform: Identity Gateway
  • 12. © 2016 ForgeRock. All rights reserved. 12
  • 13. © 2016 ForgeRock. All rights reserved. Best Practices for API Security Ludovic Poitou – Product Management Director Ludovic.Poitou@ForgeRock.com @ludomp