This presentation examines real-world examples of how API security is handled in the production APIs of Siemens software services. Important elements like authentication, access control, and validation will be discussed, along with other key aspects of API design.