I have a Rest API which is authenticated via OAUth Access token. The request body parameters posted to the API contains critical information like Customers Mobile Number and OTP code. My client is very concerned on the security. So, my question is should I ask client to encrypt these parameter values and submit to the API? I have gone through many articles and did not find anything relevant encouraging to encrypt request body data.