Scenario
You are responsible for a new public API that exposes operational data and triggers state-changing actions in an internal platform. The API will be consumed by external clients and by a few internal services, and it must support authentication, authorization, rate limiting, and audit logging from day one. A recent prototype was criticized for relying on shared tokens and for returning too much data in error responses.
Question
How would you design the API so it is secure by default without making it unusable for legitimate clients? What trade-offs would you make around authentication, authorization, request validation, logging, and failure behavior?
Practicing as: Software Engineer interview at Cobblestone EnergyHi, I'll play your Cobblestone Energy interviewer for the Software Engineer role. Candidates describe these interviews as often stressful and moderately difficult, so expect me to be direct and to the point. Take your time with the question above and answer like we're in the room.
You are practicing as a guest. Sign up free to get your answer graded with AI feedback. Your draft stays right here.


