Security Best Practices for third party access to APIs

Security is not my forte.

We are looking at a third party application for Webinars that would gather data on their end and then create/update leads in SugarCRM via a "Scribe" Connector.

What are the security implications of such a system?

Anyone have some best practices documents they can share?

Any good/bad stories by others who have done this before?

thanks,
FrancescaS