What are the duties of a JSON residual apis to prevent XSS? [duplicate]

I'm building a rest API that only supports JSON. It could one day be used by a browser-based app. Is there anything I should do to prevent XSS attacks?