Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-228

Guidelines for API Protection for Cloud-Native Systems

Date Published: June 2025

Author(s)

Ramaswamy Chandramouli (NIST), Zack Butcher (Tetrate)

Abstract

Keywords

API; API endpoint; API gateway; API key; API schema; web application firewall
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.SP.800-228
Download URL

Supplemental Material:
None available

Document History:
03/25/25: SP 800-228 (Draft)
06/27/25: SP 800-228 (Final)

Topics

Security and Privacy

general security & privacy

Technologies

cloud & virtualization