Your question is Secure API Authentication and Authorization. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
What is your approach to designing secure APIs, and how do you handle authentication and authorization vulnerabilities? Explain how you would identify threats, select authentication and authorization controls, validate inputs, protect secrets, and secure error handling. Include how you would test the controls and respond if an authentication or authorization weakness were discovered.