What are the best practices for designing a secure API architecture? I want to make sure we handle authentication and authorization correctly from the start.