A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
A collection of awesome API Security tools and resources.
Awesome Repositories
Tools
Repository |
Description |
Arjun |
HTTP parameter discovery suite |
fuzzapi |
Fuzzapi is a tool used for REST API pentesting and uses API_Fuzzer gem |
Cheatsheets
Wiki's / Encyclopedias
Checklist
Repository |
Description |
API-Security-Checklist |
Checklist of the most important security countermeasures when designing, testing, and releasing your API |
Training / Labs
Website |
Description |
Kontra - OWASP Top 10 for API |
Is a series of free interactive application security training modules that teach developers how to identify and mitigate security vulnerabilities in their web API endpoints. |
Presentations / Videos
Other useful repositories
Repository |
Description |
31-days-of-API-Security-Tips |
This challenge is Inon Shkedy's 31 days API Security Tips. |
Awesome REST |
A collaborative list of great resources about RESTful API architecture, development, test, and performance. Feel free to contribute to this on-going list. |
How to design a REST API |
How to design a REST API? - Full guide tackling security, pagination, filtering, versioning, partial answers, CORS, etc. |
API Penetration Testing |
API Penetration Testing with OWASP 2017 Test Cases |
api-security-testing-how-to-hack |
API Security Testing – How to Hack an API and Get Away with It (Part 1 of 3) |