Dataford
Interview QuestionsInterview GuidesExperiencesMock InterviewsPricing
Get started

Design a Secure Public API Boundary

Medium
MediumSecurity & InfrastructureInfrastructureDependenciesQualityAsked 1 times

Scenario

You are responsible for a new public API that exposes operational data and triggers state-changing actions in an internal platform. The API will be consumed by external clients and by a few internal services, and it must support authentication, authorization, rate limiting, and audit logging from day one. A recent prototype was criticized for relying on shared tokens and for returning too much data in error responses.

Question

How would you design the API so it is secure by default without making it unusable for legitimate clients? What trade-offs would you make around authentication, authorization, request validation, logging, and failure behavior?

Practicing as: Software Engineer interview at Cobblestone Energy

Hi, I'll play your Cobblestone Energy interviewer for the Software Engineer role. Candidates describe these interviews as often stressful and moderately difficult, so expect me to be direct and to the point. Take your time with the question above and answer like we're in the room.

Take this as a live interview session →

You are practicing as a guest. Sign up free to get your answer graded with AI feedback. Your draft stays right here.

Sign up freeI have an account
Sign up to unlock solutions
Cobblestone Energy Software Engineer Interview QuestionsCobblestone Energy Interview Questions
Next questions
CoalitionDesign a Secure Public APIMediumRestaurant Brands InternationalDesign Secure Internal APIsMediumAmerican ExpressSecure Public API DesignMedium