There is nothing fundamentally different about a RESTful API compared to any other type of HTTP request.
Use SSL to encrypt all sensitive data during transit, and think carefully about the best authentication method for your circumstances: you could consider the use of OAuth2 so that developers can authenticate your users, without requiring the users to expose their credentials.
There are a few ideas here: http://stackoverflow.com/questions/7551/best-practices-for-s...