Recommended Resources
Have a look at the following resources for more information on API security:
Collection of Resources for Building APIs
CS253: Web Security
Securing Web Applications
MIT 6.858: Computer Systems Security