# How do you feel about API security?

**URL:** <https://community.apollographql.com/t/how-do-you-feel-about-api-security/8688>\
**Category:** API Design, Strategy & Governance\
**Tags:** server, federation, schema-design\
**Created:** [March 6, 2025, 5:16pm UTC](https://community.apollographql.com/t/how-do-you-feel-about-api-security/8688 "2025-03-06T17:16:45Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aleksandar\_Susnjar](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/aleksandar_susnjar/32/5575_2.png) [@Aleksandar\_Susnjar](https://community.apollographql.com/u/Aleksandar_Susnjar)\
**Post date:** [March 6, 2025, 5:16pm UTC](https://community.apollographql.com/t/how-do-you-feel-about-api-security/8688/1 "2025-03-06T17:16:45Z")

</div>

Just trying to gauge the level of need and awareness of what it takes to expose a secure API… Before reading [anything I may think about it](https://cogito.susnjar.net/tags.html#Security):

1. Do you “feel” that the REST ecosystem is inherently more secure than GraphQL … or is it the other way around?
2. Do you feel that the RESTful model aligns better with access control, authorization and other security needs than GraphQL … or is it the other way around?

Why do you feel the way you do?

Note: no judgment here - we all have different perspectives and experiences and, thus, justifiably biased opinions.
