Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-228A (Initial Public Draft)

Guidelines for the Secure Deployment of RESTful Web APIs

Date Published: May 18, 2026
Comments Due: July 2, 2026 (public comment period is CLOSED)
Email Questions to: [email protected]

Author(s)

Ramaswamy Chandramouli (NIST), Zack Butcher (Tetrate)

Announcement

A RESTful API platform is a stateless architectural framework that leverages standard HTTP protocols to manage and exchange data as "resources," serving as the primary bridge for communication between modern web applications. These Web APIs are the most prevalent API type. Their inherent simplicity, universal compatibility with browsers, robust ecosystem of developer tools, and superior caching efficiency align with existing web infrastructure to provide scope for introducing vulnerabilities and accompanying threats of exploitation.

This document:

  • Analyzes threats to RESTful APIs across the pre-runtime and runtime phases
  • Provides guidelines for implementing a set of controls to mitigate threats
  • Complement the detailed set of controls provided in SP 800-228 by including parameters that are specific to the architectural style of RESTful Web APIs

NOTE: A call for patent claims is included in this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy – Inclusion of Patents in ITL Publications.

Abstract

Keywords

API; API endpoint; API gateway; API key; API schema; web application firewall
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.SP.800-228A.ipd
Download URL

Supplemental Material:
None available

Document History:
05/18/26: SP 800-228A (Draft)

Topics

Security and Privacy

controls, threats, vulnerabilities

Technologies

networks