Strict validation, payload sanitization, and disciplined JWT handling keep API integrations safer and maintainable.
Checklist
- Validate everything — schema-parse inputs; never trust client shape.
- Sanitize outputs — strip internal fields before responding.
- JWT discipline — short TTL, refresh rotation, server-only verification.
- Rate limit — token bucket per identity, not per IP only.
- Idempotency — dedupe webhooks by signature + key.
- HMAC webhooks — verify
x-signaturewith constant-time compare.