How do you feel about API security?

Just trying to gauge the level of need and awareness of what it takes to expose a secure API… Before reading anything I may think about it:

  1. Do you “feel” that the REST ecosystem is inherently more secure than GraphQL … or is it the other way around?
  2. Do you feel that the RESTful model aligns better with access control, authorization and other security needs than GraphQL … or is it the other way around?

Why do you feel the way you do?

Note: no judgment here - we all have different perspectives and experiences and, thus, justifiably biased opinions.