Rest API Request Body Parameters to be Encrypted?

Viewed 58

I have a Rest API which is authenticated via OAUth Access token. The request body parameters posted to the API contains critical information like Customers Mobile Number and OTP code. My client is very concerned on the security. So, my question is should I ask client to encrypt these parameter values and submit to the API? I have gone through many articles and did not find anything relevant encouraging to encrypt request body data.

1 Answers

Yes, you could encrypt the body data. The question is if you should do that. We usually do threat modeling to answer questions like this. I'd say, unless your application shots missiles TLS should be sufficient to ensure confidentiality and integrity of the whole HTTP payload. As long as you don't do defense in depth, this mitigation should be sufficient.

Related