You can use the membership API wherever you want, but I would think about whether you can really protect your web services so that they can not be abused, and because of abuse I mean that someone comes in and knocks your web services to block accounts, guess user names and passwords, and use any other functionality that you want to provide.
source share