When discussing API security, there can be a lot of confusion based on various assumptions. In an attempt to clear up some of the confusion, @dima_postnikov and I wrote a short article:
https://medium.com/oauth-2/are-your-apis-really-secure-are-you-sure-989d4bb083f
https://medium.com/oauth-2/are-your-apis-really-secure-are-you-sure-989d4bb083f