REST APIs are now the connective tissue of most modern applications. Mobile clients call them, single page applications depend on them and partners integrate against them. That visibility makes APIs an attractive target for threat actors, who have noticed that API authentication and authorisation often receive less scrutiny than the web pages of the same product. The OWASP API Security Top Ten exists for a reason, and the entries on it appear in real engagements with depressing regularity. Authentication Is Not Authorisation The terms get used interchangeably, especially in design…