Q1How would you design authentication for a REST API?
Define login, refresh, and logout flows. Use short-lived access tokens and secure refresh token rotation. Add rate limits, input validation, audit logs, and token revocation.