[ Web Proxy ]
URL:
Viewing: https://developers.cloudflare.com/use-cases/application-security/api-endpoints/ [Back]  [Original]

Secure API endpoints Cloudflare use casesSkip to content
SearchCtrlKLog in
  1. Home
  2. /Use cases
  3. /Application security
  4. /Secure API endpoints

Secure API endpoints

Last updated Apr 24, 2026Copy as MarkdownView as MarkdownAgent setup
OverviewSolutionsAPI ShieldmTLSGet started

API endpoints are vulnerable to schema violations, abuse, and unauthorized access. Cloudflare API Shield validates requests against your OpenAPI specification, and mutual TLS (mTLS) authenticates known clients with certificates.

Solutions

API Shield

Discover, secure, and monitor your APIs. Learn more about API Shield.

  • API discovery - Automatically identify API endpoints in your traffic, including undocumented ones
  • Schema validation - Reject requests that do not conform to your OpenAPI specification
  • Sequence mitigation - Detect and block API abuse patterns such as out-of-order requests

mTLS

Mutual TLS client certificate authentication. Learn more about mTLS.

  • mTLS authentication - Require client certificates for machine-to-machine API access

Get started

  1. API Shield get started
  2. Set up mTLS
PreviousProtect against client-side threatsNextOverview

Was this helpful?

YesNo
Edit pageReport issue
[]

Web Proxy Viewer  |  New URL  |  Original Page