Azure Secure API Development
Budget / Salary£20–250
TypeFreelance project
LocationRemote
Posted4 hours ago
I need a production-ready REST API in Azure that lets our existing C# application reach an Azure SQL Database from anywhere, yet keeps the database completely off the public internet. The data involved is general business data, but the connection still has to be locked down.
Authentication is two-layered. Human users must pass Microsoft Entra ID with MFA, while the application itself presents an API key on every call—no OAuth2 refresh tokens or certificates for this project. Every request must travel over TLS 1.2+ and be logged for audit purposes.
The API will expose read, write and update operations. It must connect to SQL through a system-assigned Managed Identity; no connection strings or passwords are to be stored in code or configuration. Firewall rules must be ignored, as the API will need to be accessed from any IP address in the world. The database sits behind a Private Endpoint, so the API hosting service (App Service or Function App—your call) needs VNet integration to reach it.
Deliverables
• Source-controlled C# (.NET 6/7) API with endpoints for read, write, update
• Azure infrastructure scripts (ARM/Bicep/Terraform) that create:
– App hosting with Managed Identity
– Private Endpoint for SQL and required DNS configuration
– Network rules that block all public access to SQL
• Entra ID configuration for MFA and API key validation logic
• Postman/REST Client collection that demonstrates successful calls
• Deployment and hand-over documentation, plus a brief security checklist showing how the above requirements are met
Acceptance will be based on a live walkthrough showing the C# client retrieving, inserting and updating data while the SQL server remains unreachable from the public internet and all authentication flows succeed with MFA.
Authentication is two-layered. Human users must pass Microsoft Entra ID with MFA, while the application itself presents an API key on every call—no OAuth2 refresh tokens or certificates for this project. Every request must travel over TLS 1.2+ and be logged for audit purposes.
The API will expose read, write and update operations. It must connect to SQL through a system-assigned Managed Identity; no connection strings or passwords are to be stored in code or configuration. Firewall rules must be ignored, as the API will need to be accessed from any IP address in the world. The database sits behind a Private Endpoint, so the API hosting service (App Service or Function App—your call) needs VNet integration to reach it.
Deliverables
• Source-controlled C# (.NET 6/7) API with endpoints for read, write, update
• Azure infrastructure scripts (ARM/Bicep/Terraform) that create:
– App hosting with Managed Identity
– Private Endpoint for SQL and required DNS configuration
– Network rules that block all public access to SQL
• Entra ID configuration for MFA and API key validation logic
• Postman/REST Client collection that demonstrates successful calls
• Deployment and hand-over documentation, plus a brief security checklist showing how the above requirements are met
Acceptance will be based on a live walkthrough showing the C# client retrieving, inserting and updating data while the SQL server remains unreachable from the public internet and all authentication flows succeed with MFA.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.