In this workshop, attendees will first learn the components of an API security, including API discovery, API authentication, authorization and thread detection. Next, there is a practical exercise to create an API security policy. The workshop is collaborative with feedback and suggestions provided by the facilitator. This workshop does not assume a security background or deep API expertise .