API access is controlled by RACF profiles. A mobile app user authenticated via OAuth2 is mapped to a RACF user ID, and that user ID's DB2 privileges govern what data they can access. - **TLS 1.2/1.3** — all API traffic is encrypted in transit. - **API keys** — for partner identification and basic th