API security means protecting a REST API from unauthorized access, invalid requests, data theft, abuse, and common attacks. Since a mobile application communicates with the server through APIs, API security is an important part of mobile application development.
API security protects the communication and data exchanged between a client application and the server.
React Native
↓
Secure Request
↓
REST API
↓
Authentication
↓
Authorization
↓
Validation
↓
Database
↓
Secure Response
A REST API can expose important application data. For example, a student management API may contain:
The API must ensure that only authorized users can access protected information.
HTTPS encrypts communication between the mobile application and the server.
React Native
↓
HTTPS
↓
Server
Production APIs should use HTTPS rather than sending sensitive authentication information over plain HTTP.
Authentication verifies who the user is.
Email
+
Password
↓
Login API
↓
Verify Credentials
↓
JWT Token
↓
Authenticated User
JWT-based authentication can be used for protected REST APIs.
Authorization determines what an authenticated user is allowed to do.
User Login
↓
Authentication
↓
Authorization
↓
Can User Perform This Action?
For example, a normal student may view their profile but should not be allowed to delete another student's record.
| Authentication | Authorization |
|---|---|
| Who are you? | What are you allowed to do? |
| Verifies identity | Checks permissions |
| Login/token verification | Role/permission checks |
A JWT can be issued after successful login and then sent with protected API requests.
Login
↓
JWT
↓
React Native
↓
Authorization: Bearer JWT
↓
Protected API
A common way to send a bearer token is through the Authorization header.
Authorization:
Bearer YOUR_JWT_TOKEN
The server can extract and verify the token before allowing access to protected resources.
Data received from React Native should never be automatically trusted. The API should validate request data before processing it.
Request
↓
Validate
↓
Process
↓
Database
Validation should include required fields, data types, lengths, allowed values, and application-specific rules.
Prepared statements help protect database queries from SQL injection.
$stmt = $pdo->prepare(
"SELECT *
FROM users
WHERE email = ?"
);
$stmt->execute([
$email
]);
User-provided values should not be directly concatenated into SQL queries.
Unsafe:
$sql =
"SELECT *
FROM users
WHERE email = '$email'";
Safer:
$stmt = $pdo->prepare(
"SELECT *
FROM users
WHERE email = ?"
);
$stmt->execute([
$email
]);
Passwords should never be stored as plain text.
$hash = password_hash(
$password,
PASSWORD_DEFAULT
);
During login:
if (password_verify(
$password,
$hash
)) {
// Login successful
}
The JWT signing secret is sensitive server-side information.
Do not place the JWT secret inside the React Native application.
$secretKey =
"YOUR_SERVER_SECRET";
In production, secrets should be managed securely rather than exposed in client-side code or public repositories.
Authentication tokens should not normally be sent as URL query parameters.
Avoid:
/api/profile.php?token=YOUR_TOKEN
Prefer:
Authorization:
Bearer YOUR_TOKEN
URLs can appear in logs, browser history, analytics, and other systems, so sensitive credentials should not be placed in them.
API responses should contain only information that the client actually needs.
Avoid returning:
password
password_hash
secret_key
internal_security_data
Return safe information:
{
"id": 10,
"name": "Rahul",
"email": "rahul@example.com"
}
Error responses should not expose sensitive server information.
Avoid:
{
"error":
"SQLSTATE[42S02]:
Table 'library.users'
doesn't exist..."
}
Prefer:
{
"success": false,
"message": "Server error"
}
Detailed technical errors can be logged securely on the server.
Use appropriate status codes for different security-related situations.
| Status | Meaning |
|---|---|
| 200 | Successful request |
| 201 | Resource created |
| 400 | Invalid request |
| 401 | Authentication required or invalid |
| 403 | Authenticated but not permitted |
| 404 | Resource not found |
| 422 | Validation failed |
| 429 | Too many requests |
| 500 | Server error |
Rate limiting controls how frequently a client can call an API.
Client
↓
100 requests
↓
API Rate Limit
↓
Allow / Reject
Rate limiting can help reduce abuse, excessive traffic, and repeated automated requests.
Login APIs should be protected against repeated password attempts.
Possible controls include:
CORS stands for Cross-Origin Resource Sharing. It controls which web origins are allowed to make certain browser-based requests to an API.
For React Native applications, CORS generally does not work exactly like it does for browser-based web applications because native networking is not subject to the browser's same-origin policy in the same way.
Web Browser
↓
CORS Rules
↓
API
A web API may configure an appropriate CORS policy when browser clients need access.
header(
"Access-Control-Allow-Origin: https://example.com"
);
Avoid allowing every origin in production unless that is intentionally required and understood.
File upload endpoints require additional validation.
The API should consider:
Never trust a client-provided file extension alone.
JWT access tokens should generally have an expiration time.
$payload = [
"sub" => $userId,
"iat" => time(),
"exp" => time() + 3600
];
The exp claim tells the server when the token should no
longer be accepted.
JWT access tokens are commonly designed to be stateless. If an application requires immediate invalidation before expiration, it can use a server-side revocation mechanism.
JWT
↓
Logout
↓
Revoke JTI
↓
Protected API
↓
Check Revocation
↓
Reject Revoked Token
This is especially useful when a user explicitly logs out or a token needs to be invalidated for security reasons.
Different users may have different permissions.
User
↓
JWT
↓
Role
↓
Permission Check
↓
API Resource
For example:
admin → Add / Update / Delete
student → View Own Profile
Database credentials should remain on the server.
Never put this inside React Native:
$dbUser = "root";
$dbPassword = "database-password";
The mobile application should communicate with the REST API instead of connecting directly to the database.
React Native
↓
REST API
↓
MySQL
Server-side logs can help administrators detect errors and suspicious activity.
error_log(
"API request failed"
);
Logs should not unnecessarily contain passwords, JWTs, or other sensitive credentials.
const response = await fetch(
"https://example.com/api/profile.php",
{
method: "GET",
headers: {
"Accept":
"application/json",
"Authorization":
"Bearer " + token
}
}
);
const result =
await response.json();
The application should use HTTPS and securely manage the authentication token.
React Native
↓
HTTPS
↓
Authentication
↓
JWT Verification
↓
Authorization
↓
Input Validation
↓
Prepared SQL
↓
Database
↓
Safe JSON Response
↓
React Native
Additional protections can include rate limiting, logging, token expiration, revocation, secure file uploads, and role-based access control.
A secure REST API validates incoming data, authenticates users, authorizes actions, protects database queries, uses HTTPS, handles tokens safely, and avoids exposing sensitive information.
HTTPS
+
Authentication
+
Authorization
+
Validation
+
Prepared Statements
+
Safe Responses
+
Rate Limiting
+
Secure Tokens
=
Better API Security
API security should be considered throughout the complete application, from the React Native interface to the PHP backend and database.
Question: Which practice helps protect a PHP API from SQL injection?