Description
Ship safe‑by‑default APIs.
• OpenAPI 3.1 spec + contract tests; example consumers (Node/Go/Python).
• OAuth2/OIDC integration, JWT guidelines, key rotation playbook.
• Input validation, abuse‑aware rate limits, body/size caps.
• CI security: SAST/DAST templates, SBOM artifact, dependency scanning.
• Schema‑driven mocks for consumer‑first development.
Includes security headers baseline (CSP/STS) and audit‑log fields.
Reviews
There are no reviews yet.