1) Use HTTPS 2) Use token for authentication 3) Enable cors 4) Validation input values before triggering API Method
Use HTTPSAuthenticationAuthorizationJWT (JSON Web Tokens)Security HeadersToken RevocationSecurity MiddlewareLogging and MonitoringInput ValidationCross-Origin Resource Sharing (CORS)