Well, Web API can be secured by implementing security inside Action-Filters / Message handlers. Thus, we have the following places to write/implement our security-
- Authentication Filters
- Authorization Filters
- Action Filters
- Message Handlers
Apart from these internal implementations, we can also take the benefit of the following:
- HOST level security
Web API pipeline is a great mechanism which lets developers to extend the behavior. A request is get processed by actual method only after crossing certain level of predefined stages. ex. – Handlers & Filters. It enables us to implement our security at granular level (at any level, even at method level.
The following image illustrates the same:
(pic: Web API 2.0 Security Levels)
Thus, we have many options to implement the security at many levels. We can set globally as well as up to method/function level.
Let’s explore hosting level security options. Earlier we had only IIS host but nowadays technology has evolved much and given us more options to host our applications. OWIN host is one of the leading approach to break down the IIS barrier. The following are the approaches for security implementations in these duos (IIS & Owin)-
- OWIN Middleware– If using OWIN hosting
- Http Modules– If using IIS hosting
Simplifying the things give us the following picture to know these security options.

You may also refer this article - Understanding Web API.

Pradeep SahooPosted May 9, 2016, 10:26 PM
Nice . Thanks for sharing
Anil KumarPosted Oct 22, 2015, 1:10 AM
Thank you all for your nice words!
Santhakumar MunuswamyPosted Sep 17, 2015, 10:30 AM
Thanks for nice article:)
RakeshPosted Sep 16, 2015, 11:16 AM
Good explain sir
Mohammed IbrahimPosted Sep 15, 2015, 8:05 PM
nice
Sibeesh VenuPosted Sep 15, 2015, 4:42 AM
Nice Share
Karthikeyan KPosted Sep 15, 2015, 4:14 AM
Good one sir...Thanks for sharing
Humayun Kabir MamunPosted Sep 15, 2015, 2:59 AM
Nice...
Harshad PansuriyaPosted Sep 14, 2015, 7:29 AM
nice One