API: Fundamentals and Security
Training information
- Duration: 2 days / 14 hours
- Available languages: French, English
- Request a quote
Introduction
ReST APIs have established themselves as the modern architecture for transporting data across various services. Implementing ReST APIs comes with specific security risks related to their functions. This training allows you to discover the best practices for designing, developing, and architecting ReST APIs, the associated tools, and the methods to effectively mitigate these risks.
General information
Target Audience: Project managers, developers, business analysts, and API product owners. Prerequisites: None.
Target Competencies:
-
Develop, maintain, and integrate APIs.
-
Advise on API design.
-
Troubleshoot and debug issues.
-
Secure and maintain API security.
Learning Objectives:
-
Define APIs and their challenges.
-
Identify best practices for designing and developing ReST APIs.
-
Manage your API security.
Program
Part 1: API Architecture & Design Foundations (7 Hours)
-
1.1 Introduction to Modern APIs: Contextualizing APIs in the digital ecosystem, JSON structural deep-dive, TCP/IP fundamentals, and HTTP protocol mechanics.
-
1.2 RESTful Structure & Implementation: URI design conventions, mastering HTTP verbs, header manipulation, parameter management, and contrasting ReSTful architecture with raw ReST principles.
-
1.3 Design & Publication Tooling: RAML and OAS specification writing, Postman workspace configurations, setting up developer portals, and structuring self-service documentation.
Part 2: API Security & Risk Mitigation (7 Hours)
-
2.1 The API Threat Landscape: Business impacts of breaches, deep dive into the OWASP API Security Top 10, and identifying common architectural vulnerabilities.
-
2.2 Authentication & Authorization Frameworks: Key management strategies, TLS/SSL encryption standards, HTTPS enforcement, OAuth 2.0 flows, and granular permission architectures.
-
2.3 Hands-On Security Troubleshooting: Live debugging of secure connections, traffic interception exercises, and applying rate limiting and threat protection policies.
Logistical information
-
Duration: 2 days (14 hours).
- Capacity: 12 participants maximum.
-
Teaching Methods: Alternation of theoretical and practical inputs, expert API trainer, course materials and application documents provided at the end of the training.
-
Assessment: Continuous exercises and a final self-assessment.
-
Accessibility: Accessible to individuals with motor disabilities.