api-design
Safeguard articles tagged "api-design" — guides, analysis, and best practices for software supply chain and application security.
4 articles
An Idempotency Key That Only Checks Prior Receipt Protects Nothing
A client retries a timed-out payment request. Both copies arrive close together, both pass the check for whether the key exists, because neither has finished processing yet, and both charge the card.
What Your Identifiers Tell the World
A random identifier is not an access control. What identifier design does affect is discovery, inference and what leaks when a URL travels, and a sequential integer in a URL publishes your customer count.
Design the API Key So It Can Be Found When It Leaks
A high-entropy string with no marker is invisible to every secret scanner, which makes yours the product that finds out last. A few decisions about the format buy a great deal.
A Bare 400 Is Not a Security Posture
Empty error bodies get written by people worried about leaking internals, which is a real concern answered by the wrong control. Be precise about the caller's input, opaque about the system's state.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.