Single Page Applications (SPAs) have taken up prime real estate in the digital city. SPAs have a secret ally: Application Programming Interfaces, or APIs. Cross-Site Scripting, or XSS, can turn our trusty courier, the API, into an unwitting accomplice in a malicious scheme.