You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 800-228A (Initial Public Draft) Guidelines for the Secure Deployment of RESTful Web APIs Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: May 18, 2026 Comments Due: July 2, 2026 (public comment period is CLOSED) Email Questions to: [email protected] Author(s) Ramaswamy Chandramouli (NIST) , Zack Butcher (Tetrate) Announcement A RESTful API platform is a stateless architectural framework that leverages standard HTTP protocols to manage and exchange data as "resources," serving as the primary bridge for communication between modern web applications. These Web APIs are the most prevalent API type. Their inherent simplicity, universal compatibility with browsers, robust ecosystem of developer tools, and superior caching efficiency align with existing web infrastructure to provide scope for introducing vulnerabilities and accompanying threats of exploitation. This document: Analyzes threats to RESTful APIs across the pre-runtime and runtime phases Provides guidelines for implementing a set of controls to mitigate threats Complement the detailed set of controls provided in SP 800-228 by including parameters that are specific to the architectural style of RESTful Web APIs NOTE: A call for patent claims is included in this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy – Inclusion of Patents in ITL Publications . Abstract A RESTful API platform is a stateless architectural framework that leverages standard HTTP protocols to manage and exchange data as "resources," serving as the primary bridge for communication between modern web applications. This alignment with Web is the reason they are also called Web APIs and remain the most prevalent API type. Their inherent simplicity (creating a low barrier for entry), universal compatibility with browsers, robust ecosystem of developer tools and superior caching efficiency that aligns naturally with existing web infrastructure gives scope for introducing vulnerabilities and accompanying threats of exploitation. This document analyzes those threats to RESTful APIs and provides guidance for implementing a set of associated mitigating controls. Thus, it also complements the detailed set of controls provided in SP 800-228 by including parameters that are specific to the architectural style of RESTful Web APIs. A RESTful API platform is a stateless architectural framework that leverages standard HTTP protocols to manage and exchange data as "resources," serving as the primary bridge for communication between modern web applications. This alignment with Web is the reason they are also called Web APIs and... See full abstract A RESTful API platform is a stateless architectural framework that leverages standard HTTP protocols to manage and exchange data as "resources," serving as the primary bridge for communication between modern web applications. This alignment with Web is the reason they are also called Web APIs and remain the most prevalent API type. Their inherent simplicity (creating a low barrier for entry), universal compatibility with browsers, robust ecosystem of developer tools and superior caching efficiency that aligns naturally with existing web infrastructure gives scope for introducing vulnerabilities and accompanying threats of exploitation. This document analyzes those threats to RESTful APIs and provides guidance for implementing a set of associated mitigating controls. Thus, it also complements the detailed set of controls provided in SP 800-228 by including parameters that are specific to the architectural style of RESTful Web APIs. Hide full abstract Keywords API ; API endpoint ; API gateway ; API key ; API schema ; web application firewall Control Families None selected Documentation Publication: https://doi.org/10.6028/NIST.SP.800-228A.ipd Download URL Supplemental Material: None available Document History: 05/18/26: SP 800-228A (Draft) Topics Security and Privacy controls , threats , vulnerabilities Technologies networks HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov