data:image/s3,"s3://crabby-images/0ee12/0ee12f48098e694fb53a916a026e62b68cd1f04e" alt=""
My advice for running a public-facing API, coming from 11 years of operating the Pushover (@pushover) API:
- Host the API on its own hostname
- Don't be too liberal in what you accept
- Avoid OAuth if you can
- Log a unique id with every request
- Be descriptive in your error responses
- Use prefixed tokens
- Stay on top of failures