shieldfy/API-Security-Checklist resource
Checklist of the most important security countermeasures when designing, testing, and releasing your API observed · 2026-08-28
Health v2 · maintenance only
74/100
- Activity 93
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3343
- days_rel: n/a
- days_push: 43
- n_releases_24m: 0
Adoption not part of the score
23306 stars · 2651 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
A community-maintained checklist of essential API security countermeasures covering authentication, authorization, input validation, and more. It is a reference document, not executable software.
Use cases
- secure my REST API before release
- API security best practices checklist
- review API design for security flaws
- learn about JWT and OAuth2 security pitfalls
- audit checklist for API penetration testing
When to choose
- designing, testing, or releasing an API and want a security review checklist
- training developers on API security fundamentals
When to avoid
- you need a tool that scans or tests APIs automatically
- you need executable code or a library to include in your project
Facets
learning-resource · maturity active
security security apis developer-tools cross-platform api-security checklist jwt oauth2 best-practices
1 source
- readme: https://github.com/shieldfy/API-Security-Checklist · fetched 2026-08-28 · 813e9a71bb17
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| shieldfy/API-Security-Checklist | main | 74 |
For agents
markdown · JSON · MCP: product_card(name="shieldfy/API-Security-Checklist")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem