Skip to content
Tech Interview Prep home
Technical interview guide

API Authentication & Authorization

Verifying who's calling an API (authentication) and what they're allowed to do (authorization) — API keys, OAuth, and JWTs.

Read
24 min
Practice MCQs
25
Interview QA
25
Edition
v3
Editorial status
Reviewed

Scope: HTTP Semantics RFC 9110 and OpenAPI Specification 3.2.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Explain the difference between authentication and authorisation, and why it matters.

QA-2

How would you prevent broken object-level authorisation?

QA-3

Explain what OAuth 2.0 is for and what it is not for.

QA-4

Walk through the authorization code flow with PKCE and explain what each step protects.

QA-5

What are the trade-offs between stateless JWTs and opaque tokens?

QA-6

How would you validate a JWT correctly, and what attacks does incomplete validation enable?

QA-7

How would you design the permission model for a multi-tenant SaaS application?

QA-8

Where should a browser client store an access token, and what are the risks?

QA-9

How would you handle authentication between internal services?

QA-10

How would you design API key management for third-party integrators?

QA-11

Compare role-based, attribute-based and relationship-based access control.

QA-12

Why do OAuth systems use both an access token and a refresh token, and how do rotation and reuse detection limit the damage when one of them is stolen?

QA-13

How would you implement logout in a system using stateless tokens?

QA-14

How do you protect authentication endpoints from abuse?

QA-15

What is the difference between an ID token and an access token, and why does it matter?

QA-16

How would you handle permission changes taking effect for active sessions?

QA-17

How would you test the authorisation of an API thoroughly?

QA-18

What would you do if you discovered an authorisation vulnerability in production?

QA-19

How do RBAC and ABAC differ in API authorization, and when would you introduce an external policy engine like OPA or Zanzibar-style relation-based access control?

QA-20

What are the risks of a token that never expires?

QA-21

How would you introduce authorisation into an API that has none?

QA-22

What is the confused deputy problem in the context of APIs?

QA-23

How would you decide what an audit log for authentication and authorisation should contain?

QA-24

What would make you reject an authentication design in review?

QA-25

How do authentication and authorisation interact with an API's usability?