In 2018, at least 85% of organisations consider web APIs and API-based integration fundamental to their business strategy and continued success. However, the explosion of APIs is creating incremental security risks that must be addressed, considering that over half of the internet traffic is bot or API based. In 2017, APIs appeared for the first time on the OWASP Top 10 Application Security Risks, with the warning that “attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes.”Learning Outcomes:The sources of API security vulnerabilities, web API How DevOps teams can build more secure APIs and the typical vulnerabilities to look for Strategies for defending against the threats, including machine learning techniques that are used for detecting botnet activities Anatomy of API attacks: real case examples of application attacks that focused on API endpoint. Prioritising human traffic over API traffic, and API traffic shaping.