Cracking the code: demystifying API Security