Agent skill

API Security Design

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

MITAuto-check passedBackend & APIs

Install API Security Design

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill api-security-design -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills api-security-design --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/api-security-design .claude/skills/api-security-design && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-security-design
GitHub stars
175
Token cost
~2.2k tokens
SKILL.md length
1,086 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

  • Works in 8 steps: Authentication at the gateway with Entra… → Authorization in the backend - Enforce… → Apply gateway protections (APIM) -… → …
  • General application security
  • SKILL.md covers When to use, Pick the right control per…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

API Security Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API Security Top 10 and Azure API Management. WHEN: API security design, secure API, OWASP API Top 10, API authentication, API gateway security, rate limiting, validate JWT, protect backend API, API Management security policies, secure API architecture, BOLA, BFLA. DO NOT USE for general application security or web app…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Web application vulnerabilities, Authentication and Rate limiting. It works with Azure API Management and Microsoft Azure. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • General application security
  • Web app design (use security-architecture / threat-modelling)
  • For API runtime detection only (use defender-for-apis)

Example prompts

  • “/api-security-design”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Authentication at the gateway with Entra ID - Require OAuth 2.0 / OpenID Connect via
  2. Authorization in the backend - Enforce least-privilege scopes/roles in the JWT, then
  3. Apply gateway protections (APIM) - Configure: rate-limit and quota policies per
  4. Transport and secrets - Enforce TLS 1.2+ on every endpoint, use mTLS to backends
  5. Exposure and network controls - Front public APIs with WAF (Application Gateway or
  6. Validate input rigorously - Validate against the OpenAPI schema at the gateway; reject
  7. Add runtime threat detection - Enable Microsoft Defender for APIs for APIM-fronted
  8. Catalog and lifecycle the APIs - Inventory every API in APIM (or your gateway), tag by

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Security Design loads about 2.2k tokens when it runs. Until then it costs about 162 tokens; SKILL.md has 1,086 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~162
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 1,086 words, ~2,243 tokens.

Download SKILL.mdSave it as .claude/skills/api-security-design/SKILL.md (or your agent's skills folder).
name
api-security-design
description
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API Security Top 10 and Azure API Management. WHEN: API security design, secure API, OWASP API Top 10, API authentication, API gateway security, rate limiting, validate JWT, protect backend API, API Management security policies, secure API architecture, BOLA, BFLA. DO NOT USE for general application security or web app design (use security-architecture / threat-modelling) or for API runtime detection only (use defender-for-apis).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

API Security Design

Secure API design protects backend services and data from abuse and the OWASP API Security Top 10 risks - broken object-level authorization (BOLA), broken authentication, broken function-level authorization (BFLA), unrestricted resource consumption, server-side request forgery, and more. On Azure, Azure API Management (APIM) is the primary policy enforcement point, paired with WAF, Entra ID, Key Vault, and Defender for APIs.

When to use

Designing or reviewing the security of APIs - especially external-facing, partner-facing, or sensitive-data APIs - before they go live or as part of a recurring design review.

Do not use this skill for:

  • General application or web app security (use security-architecture, threat-modelling)
  • API runtime detection and posture only (use defender-for-apis)
  • Front-end / SPA design (use web app security guidance)

Pick the right control per OWASP API risk

OWASP API Top 10 riskPrimary controlWhere it lives
API1 - BOLA (object-level auth)Per-object authorization checkBackend code (gateway cannot fully cover)
API2 - Broken authenticationOAuth 2.0 / OIDC with Entra ID, validate-jwtGateway + Entra
API3 - Broken object property authSchema validation + response filteringBackend + gateway
API4 - Unrestricted resource consumptionRate limit, quota, payload size, timeoutGateway (APIM)
API5 - BFLA (function-level auth)Role/scope check on each operationBackend code
API6 - Unrestricted access to sensitive flowsStep-up auth, anti-abuse rulesEntra + gateway
API7 - SSRFOutbound URL allow-list + egress controlsBackend + network
API8 - Security misconfigurationIaC + APIM policy templatesDevOps + gateway
API9 - Improper inventory managementAPI catalog + lifecycle in APIMAPIM + governance
API10 - Unsafe consumption of third-party APIsValidate upstream responses, timeoutsBackend

Rule of thumb: BOLA and BFLA are the top two API risks and cannot be fully fixed at the gateway - the backend must enforce per-object and per-function authorization. The gateway is necessary but not sufficient.

Approach

  1. Authentication at the gateway with Entra ID - Require OAuth 2.0 / OpenID Connect via Microsoft Entra ID; validate JWTs at APIM with the validate-jwt policy (issuer, audience, signing key, expiration, required claims). Avoid static API keys as the only control - rotate them aggressively if used at all. Verify: a request with an invalid or expired JWT is rejected at the gateway; logs show the rejection reason.
  2. Authorization in the backend - Enforce least-privilege scopes/roles in the JWT, then check object-level and function-level authorization in the backend on every call. The gateway sees the caller; only the backend knows whether the caller owns the object. Verify: a test JWT for user A returns 403 when requesting user B's data, even though the gateway lets the call through.
  3. Apply gateway protections (APIM) - Configure: rate-limit and quota policies per subscription/IP/identity, IP filtering for allow-lists, request and response validation against the OpenAPI schema, payload size limits, timeouts, and CORS scoped to known origins. Verify: a request exceeding the rate limit returns 429; an oversized payload is rejected; a request not matching the OpenAPI schema is rejected.
  4. Transport and secrets - Enforce TLS 1.2+ on every endpoint, use mTLS to backends where threat model requires it, and store all secrets (backend credentials, signing keys) in Azure Key Vault referenced via APIM named values with a managed identity. No secrets in policy XML, no secrets in code. Verify: no secret literal appears in APIM policies or source repo; APIM uses managed identity to fetch Key Vault references at runtime.
  5. Exposure and network controls - Front public APIs with WAF (Application Gateway or Azure Front Door) for L7 protection (OWASP Core Rule Set), and use Private Endpoints to keep backends off the public internet. Internal APIs should not have a public route. Verify: a port scan of the public IP reaches WAF/APIM only; backends are not reachable directly from the internet.
  6. Validate input rigorously - Validate against the OpenAPI schema at the gateway; reject unexpected fields, oversized payloads, and malformed types. Backend code re-validates business invariants - never trust the gateway alone. Verify: fuzz testing on the API produces 4xx responses, not 5xx; no input class causes a crash or stack trace leak.
  7. Add runtime threat detection - Enable Microsoft Defender for APIs for APIM-fronted APIs to detect runtime threats (suspicious access patterns, sensitive-data exposure, reconnaissance, OWASP-aligned attacks). Verify: a deliberately abusive test client triggers a Defender for APIs alert.
  8. Catalog and lifecycle the APIs - Inventory every API in APIM (or your gateway), tag by sensitivity and ownership, and retire deprecated versions on a schedule. Shadow APIs
    • undocumented, unmonitored - are the most common breach path.
Show full SKILL.md (361 more words)Show less

Guardrails

  • BOLA/BFLA are the top API risks - authorization must be enforced server-side per object and per function. The gateway can see the caller but not which objects they may touch.
  • Don't rely on the gateway alone - defence in depth across gateway + backend. Single layers fail; layered controls mean a misconfiguration in one place does not equal breach.
  • Validate input against a schema; reject unexpected fields and oversized payloads. The most common API CVE is "we accepted what we did not expect".
  • No static API keys as sole authentication. Move to OAuth 2.0 + Entra ID. If keys remain for partner compatibility, rotate aggressively and rate-limit hard.
  • Treat the API inventory as an asset - shadow APIs are unmanaged risk. Discovery + catalog is part of API security, not just operations.
  • Backend re-validation is not duplication - it is the only place per-object authorization can land safely.

Common anti-patterns

  • "We have JWT validation at the gateway, we are secure." Missing BOLA/BFLA checks in the backend - the most common API breach pattern.
  • Static API keys with no rate limit and no rotation. Single credential leak = full exposure with no detection.
  • No schema validation at the gateway. Backends crash on malformed input and leak stack traces; fuzzing finds bugs in production rather than in test.
  • Secrets in APIM policy XML or repo. First credential rotation incident exposes them permanently in history.
  • Public backend even with APIM in front. Anyone who finds the backend URL bypasses the gateway. Use Private Endpoints / VNet integration.
  • No API catalog. Shadow APIs are the dominant external API breach pattern. If you cannot list them you cannot secure them.

Example prompts

  • Design a secure API on Azure API Management aligned to the OWASP API Security Top 10.
  • How do I validate JWTs at the gateway instead of relying on static API keys?
  • Configure rate limiting and payload validation to protect a backend API.
  • Review my API authentication and authorization design for least privilege.
  • What controls cover BOLA and BFLA on Azure API Management?

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/api-security-design of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

API Security Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Security Design compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Security Design this skillvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
API Auditbriiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT
Springboot Securityaffaan-m/ECC276k5 repos~2kAutomated safety check: PassMIT
Laravel Securityaffaan-m/ECC276k3 repos~2kAutomated safety check: PassMIT
API Security Best Practicesdavila7/claude-code-templates32k8 repos~5.8kAutomated safety check: PassMIT
Quarkus Securityaffaan-m/ECC276k1 repos~3.1kAutomated safety check: PassMIT

Similar skills

  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

    276k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check passed
  • Laravel Security

    affaan-m/ECC

    Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.

    276k GitHub starsUsed in 3 repos~2k tokens
    Backend & APIsAuto-check passed
  • API Security Best Practices

    davila7/claude-code-templates

    Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities

    32k GitHub starsUsed in 8 repos~5.8k tokens
    Backend & APIsAuto-check passed
  • Quarkus Security

    affaan-m/ECC

    Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…

    276k GitHub starsUsed in 1 repo~3.1k tokens
    Backend & APIsAuto-check passed
  • Security Patterns

    CloudAI-X/claude-workflow-v2

    Implements authentication, authorization, encryption, secrets management, and security hardening patterns.

    1.4k GitHub stars~3.6k tokensUpdated 3 days ago
    Backend & APIsAuto-check: notes

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Firewall

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Firewall — managed cloud-native L3-L7 stateful network firewall for centralised egress, east-west, and ingress control.

    175 GitHub stars~1.7k tokensUpdated 3 mo ago
    Auto-check passed

Questions about API Security Design

What does API Security Design do?

Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…. API Security Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API Security Top 10 and Azure API Management.

When should I use API Security Design?

API Security Design fits situations like: general application security; web app design (use security-architecture / threat-modelling); for API runtime detection only (use defender-for-apis).

How do I install API Security Design in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill api-security-design -a claude-code`. Or copy the skill folder (skills/api-security-design in vinayaklatthe/microsoft-security-skills) into .claude/skills/api-security-design in your project. Claude Code loads it when a task matches its description.

How do I install API Security Design in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill api-security-design -a codex`. Or copy the skill folder (skills/api-security-design in vinayaklatthe/microsoft-security-skills) into .agents/skills/api-security-design in your project. Codex loads it when a task matches its description.

Can I use API Security Design in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill api-security-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-security-design, .gemini/skills/api-security-design, .github/skills/api-security-design and .opencode/skills/api-security-design in your project.

What does API Security Design need to run?

SKILL.md names no scripts, command-line tools or credentials: API Security Design is instructions for the agent only.

Does API Security Design access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is API Security Design safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Security Design use?

API Security Design is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Security Design use?

About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Security Design?

Skills that share tags, products or a category with API Security Design: API Audit (briiirussell/cybersecurity-skills, 413 stars), Springboot Security (affaan-m/ECC, 276k stars), Laravel Security (affaan-m/ECC, 276k stars) and API Security Best Practices (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Security Design?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.