Department of Business Administration – IT Management, Western Governors University, United States of America.
Received on 28 September 2022; revised on 19 November 2022; accepted on 28 November 2022
Modern banking—including open banking and digital car loan platforms—relies on interconnected APIs across banks, fintech’s, identity providers, credit bureaus, dealerships, and customers. Such ecosystems enable innovation (e.g., real time financial data sharing, streamlined loan origination), but also expand exposure to threats like broken authentication, authorization misconfigurations (e.g., IDOR), injection attacks, data leakage, replay attacks, DoS, and more.
Profiles emerging threats across open banking and digital car loan APIs.
Presents technical mitigations using OAuth 2.0, OpenID Connect, PKCE, and API Gateways.
Offers a refined secure architecture combining gateways, JWT handling, MTLS, RBAC/ABAC, WAFs, encryption, and monitoring.
Demonstrates how to secure a car loan API flow—from login to loan issuance—with NFT style nonces, token binding, scope enforcement, and logging.
Reviews operations practices: DevSecOps, auditing, incident response, and regulatory compliance.
Explores future innovations: DPoP (proof-of-possession), OAuth 2.1 updates, token binding, AI-driven threat detection, SSI, and standards-based API governance.
API Security; Open Banking; OAuth 2.0; OpenID Connect (OIDC); API Gateway; Digital Transformation; Car Loan API Security; API Threat Landscape; Token Binding; PKCE; Mutual TLS; Secure API Architecture; API Vulnerability Mitigation; Zero Trust API Security; DevSecOps for APIs
Get Your e Certificate of Publication using below link
Preview Article PDF
Ashish Hota. Securing API Ecosystems in Digital Banking Transformation. World Journal of Advanced Engineering Technology and Sciences, 2022, 07(02), 371-378. Article DOI: https://doi.org/10.30574/wjaets.2022.7.2.0126