Skip to content
53

awesome-apisec

A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.

3.9k stars656 forks150 entriesLast push May 1, 2026 (5 months ago)License GPL-3.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

API Keys: Find and validate

API Guesser

Simple website to guess API Key / OAuth Token by Muhammad Daffa

In 2 lists

API Key Leaks: Tools and exploits

An API key is a unique identifier that is used to authenticate requests associated with your project. Some developers might hardcode them or leave it on public shares.

In 12 listsDetails

Key-Checker

Go scripts for checking API key / access token validity.

In 2 lists

Keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

In 2 lists

Private key usage verification

Driftwood is a tool that can enable you to lookup whether a private key is used for things like TLS or as a GitHub SSH key for a user.

In 2 lists

Mantra

A tool used to hunt down API key leaks in JS files and pages

Cheatsheets

GraphQL Cheat Sheet

GraphQL - OWASP Cheat Sheet Series

In 3 lists

JSON Web Token Security Cheat Sheet

PentesterLab - JSON Web Token Security Cheat Sheet

Injection Prevention Cheat Sheet

Injection - OWASP Cheat Sheet Series

Microservices Security Cheat Sheet

Microservices - OWASP Security Cheat Sheet

OWASP API Security Top 10

42Crunch - OWASP API Security Top 10

REST Assessment Cheat Sheet

REST Assessment - OWASP Cheat Sheet Series

REST Security Cheat Sheet

REST Security - OWASP Cheat Sheet Series

Conferences

APIsecure

The world's first conference dedicated to API threat management; bringing together breakers, defenders, and solutions in API security.

Deliberately vulnerable APIs

APISandbox

Pre-Built Vulnerable Multiple API Scenarios Environments Based on Docker-Compose.

In 2 lists

Bookstore

TryHackMe room - A Beginner level box with basic web enumeration and REST API Fuzzing.

crAPI

completely ridiculous API (crAPI)

In 2 lists

Damn Vulnerable GraphQL Application

Damn Vulnerable GraphQL Application is intentionally vulnerable implementation of Facebook's GraphQL technology to learn and practice GraphQL Security.

In 2 lists

Damn Vulnerable Micro Services

This is a vulnerable microservice written in many languages to demonstrating OWASP API Top Security Risk (under development).

Damn Vulnerable RESTaurant API Game

Damn Vulnerable Restaurant is an intentionally vulnerable Web API game for learning and training purposes dedicated to developers, ethical hackers and security engineers.

In 2 lists

Damn Vulnerable Web Services

Damn Vulnerable Web Services is a vulnerable web service/API/application that we can use to learn webservices/API vulnerabilities.

In 2 lists

Generic-University

Vulnerable API with Laravel App

node-api-goat

A simple Express.JS REST API application that exposes endpoints with code that contains vulnerabilities.

Pixi

The Pixi module is a MEAN Stack web app with wildly insecure APIs!

poc-graphql

Research on GraphQL from an AppSec point of view.

REST API Goat

This is a "Goat" project so you can get familiar with REST API testing.

VAmPI

Vulnerable REST API with OWASP top 10 vulnerabilities for APIs

In 2 lists

vAPI

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

In 2 lists

vulnapi

Intentionaly very vulnerable API with bonus bad coding practices.

vulnerable-graphql-api

A very vulnerable implementation of a GraphQL API.

Websheep

Websheep is an app based on a willingly vulnerable ReSTful APIs.

VulnerableApp4APISecurity

This repository was developed using .NET 7.0 API technology based on findings listed in the OWASP 2019 API Security Top 10.

Design, Architecture, Development

The API Specification Toolbox

This Toolbox goal is to try and map out all of the different API specifications in use, as well as the services, tooling, extensions, and other supporting elements.

Understanding gRPC, OpenAPI and REST

gRPC vs REST: Understanding gRPC, OpenAPI and REST and when to use them in API design

API security design best practices

API security design best practices for enterprise and public cloud.

REST API Design Guide

This design guide or style guide contains best practices suitable for most REST APIs.

How to design a REST API

How to design a REST API? - Full guide tackling security, pagination, filtering, versioning, partial answers, CORS, etc.

In 2 lists

Awesome REST

A collaborative list of great resources about RESTful API architecture, development, test, and performance. Feel free to contribute to this ongoing list.

In 6 listsDetails

Collect API Requirements

Collecting Requirements for your API with APIOps Cycles.

API Audit

API Audit is a method to ensure APIs are matching the API Design guidelines. It also helps check for usability, security and API management platform compatibility.

Enumeration, Scanning and exploration steps

Burp API enumeration

Using Burp to Enumerate a REST API

ZAP scanning

Scanning APIs with ZAP

ZAP exploring

Exploring APIs with ZAP

w3af scanning

Scan REST APIs with w3af

Firewalls

BunkerWeb

Open-source and next-generation Web Application Firewall (WAF) with integrated ModSecurity, OWASP Core Rule Set, automatic bot blocking, rate limiting, and comprehensive protection for web services and APIs.

In 7 listsDetails

Wallarm Free API Firewall

Fast and light-weight API proxy firewall for request and response validation by OpenAPI specs.

Fuzzing, SecLists, Wordlists

API names wordlist

A wordlist of API names for web application assessments

In 2 lists

API HTTP requests methods

HTTP requests methods wordlist by @danielmiessler

In 14 listsDetails

API Routes Wordlists

API Routes - Automated Wordlists provided by Assetnote

In 2 lists

Filenames by fuzz.txt

Potentially dangerous files

In 3 lists

Fuzzing APIs

Fuzzing APIs chapter from "The Fuzzing Book".

Hacking-APIs

Wordlists and API paths by @hapi_hacker

List of API endpoints & objects

A list of 3203 common API endpoints and objects designed for fuzzing.

GraphQL wordlist

The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.

HTTP 101

Know your HTTP Headers!

HTTP Headers: a simplified and comprehensive table.

Know your HTTP Methods!

HTTP Methods: a simplified and comprehensive table.

Know your HTTP Status codes!

HTTP Status codes: a simplified and comprehensive table.

HTTP Status Codes

httpstatuses.com is an easy to reference database of HTTP Status Codes with their definitions and helpful code references all in one place.

In 2 lists

Know your HTTP * Well

HTTP headers, media-types, methods, relations and status codes, all summarized and linking to their specification.

Mind maps

Abhay Bhargav

Mind map: REST API defenses

Cypro AB

Mind map: API Pentesting - ATTACK

David Sopas

Organize your API security assessment by using MindAPI

Harsh Bothra

Mind map: XML attacks

Mosaad Sallam

Mind map: GraphQL Security Testing

Mufaddal Masalawala

Mind map: IDOR Techniques

Other resources

API Hacking Articles

API Hacking Fundamentals, Tools, Techniques, Fails and Mindset articles.

API Security best practices guide

API Security Best Practices MegaGuide

API Security: The Complete Guide

API Security, The Complete Guide

API Penetration Testing

API Penetration Testing with OWASP 2017 Test Cases.

API Penetration Testing Report

Anonymised API Penetration Testing Report - vendor sample template

API Pentesting with Swagger Files

Simplifying API Pentesting With Swagger Files.

API security path resources

Resources to help out in the API security path; diverse content from talks/webinards/videos, must read, writeups, bola/idors, oauth, jwt, rate limit, ssrf and practice entries.

API Security Testing

Principles of API Security Testing and how to perform a Security Test on an API.

Finding and Exploiting Web App APIs

Finding and Exploiting Unintended Functionality in Main Web App APIs

How to Hack an API and Get Away with It

How to Hack an API and Get Away with It (Part 1 of 3).

How to Hack APIs in 2021

How to Hack APIs in 2021

How to Hack API in 60 minutes with Open Source Tools

How to Hack API in 60 minutes with Open Source Tools

GraphQL penetration testing

How to exploit GraphQL endpoint: introspection, query, mutations & tools.

Fixing the 13 most common GraphQL Vulnerabilities

GraphQL Security Guide, Fixing the 13 most common GraphQL Vulnerabilities to make your API production ready.

Hacking APIs - Notes from Bug Bounty Bootcamp

My Notes on Hacking APIs from Bug Bounty Bootcamp.

SOAP Security Vulnerabilities and Prevention

SOAP Security, Top Vulnerabilities and How to Prevent Them.

API and microservice security

What are API and microservice security?

Strengthening Your API Security Posture

Strengthening Your API Security Posture – Ford Motor Company.

The Fault in Our Stars

Security Implications of AWS API Gateway Lambda Authorizers and IAM Wildcard Expansion.

Playlists

Everything API Hacking

A video collection from Katie Paxton-Fear, @InsiderPhD, and other people creating a playlist of API hacking knowledge!

API hacking

API hacking videos from @theXSSrat

Podcasts

Hacking APIs

The Hacker Mind Podcast: Hacking APIs

Hack Your API-Security Testing

21: Troy Hunt: Hack Your API-Security Testing.

The OWASP API Security Project

Erez Yalon — The OWASP API Security Project

Episode 38 API Security Best Practices

We Hack Purple Podcast Episode 38 API Security Best Practices.

Presentations, Videos

pentesting-rest-apis

Pentesting Rest API's by Gaurang Bhatnagar

Securing your APIs

"How Secure are you APIs?" - Securing your APIs: OWASP API Top 10 2019, Case Study and Demo.

api-security-testing-for-hackers

API Security Testing For Hackers

bad-api-hapi-hackers

Bad API, hAPI Hackers!

disclosing-information-via-your-apis

Hidden in Plain Site: Disclosing Information via Your APIs.

rest-in-peace-abusing-graphql

REST in Peace: Abusing GraphQL to Attack Underlying Infrastructure.

Projects

owasp api security project

OWASP API Security Project - API Security Top 10

In 2 lists

Security APIs

awesome-security-apis

A collective list of public JSON APIs for use in security.

API Description Specifications

API Blueprint

API Blueprint Specification

In 2 lists

AscyncAPI

AsyncAPI Specification

OpenAPI

OpenAPI Specification

JSON API

JSON API Specification

GraphQL

GraphQL Specification

In 2 lists

RAML

RAML Specification

In 3 lists

Tools

BatchQL

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations.

clairvoyance

Obtain GraphQL API schema despite disabled introspection!

In 2 lists

InQL

InQL - A Burp Extension for GraphQL Security Testing.

In 3 lists

graphinder

Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce.

In 2 lists

graphql-cop

Security Auditor Utility for GraphQL APIs.

In 2 lists

GraphQLmap

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes.

In 2 lists

graphql-path-enum

Tool that lists the different ways of reaching a given type in a GraphQL schema.

graphql-playground

GraphQL IDE for better development workflows (GraphQL Subscriptions, interactive docs & collaboration)

In 2 lists

graphql-threat-matrix

GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations.

graphw00f

graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.

In 2 lists

goctopus

Blazing fast GraphQL discovery & fingerprinting toolbox.

In 2 lists

graphql-armor

The missing GraphQL security security layer for Apollo GraphQL and Yoga / Envelop servers

In 2 lists

Akto

API discovery, automated business logic testing and runtime detection

APIClarity

Reconstruct Open API Specifications from real-time workload traffic seamlessly.

APICheck

The DevSecOps toolset for REST APIs.

APIKit

APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

In 2 lists

APIFuzzer

Fuzz test your application using your OpenAPI or Swagger API definition without coding.

Arjun

HTTP parameter discovery suite.

In 3 lists

Astra

Automated Security Testing For REST API's.

In 2 lists

Automatic API Attack Tool

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

In 2 lists

CATS

CATS is a REST API Fuzzer and negative testing tool for OpenAPI endpoints.

In 2 lists

CentralMind/Gateway

Generate production ready APIs using AI based on database schema and data, optimized for AI-Agents. Supports PostgreSQL, Clickhouse, MySQL, Snowflake, BigQuery.

In 4 listsDetails

Cherrybomb

Stop half-done API specifications with a CLI tool that helps you avoid undefined user behaviour by validating your API specifications.

In 2 lists

fuzz-lightyear

A pytest-inspired, DAST framework, capable of identifying vulnerabilities in a distributed, micro-service ecosystem through chaos engineering testing and stateful, Swagger fuzzing.

fuzzapi

Fuzzapi is a tool used for REST API pentesting anTnT-Fuzzerd uses API_Fuzzer gem.

In 2 lists

ffuf

Fast web fuzzer written in Go.

In 5 listsDetails

gotestwaf

An open-source project in Golang to test different web application firewalls (WAF) for detection logic and bypasses

In 3 lists

kiterunner

Contextual Content Discovery Tool.

In 4 listsDetails

Metlo

Open-source API security tool to discover, inventory, test, and protect your APIs.

mitmproxy2swagger

Automagically reverse-engineer REST APIs via capturing traffic

In 2 lists

OFFAT

The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.

Optic

Verify the accuracy of your OpenAPI 3.x spec using real traffic and automatically apply patches that keep it up-to-date

In 4 listsDetails

REST-Attacker

Designed as a proof-of-concept for the feasibility of testing generic real-world REST implementations. Its goal is to provide a framework for REST security research.

RESTler

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.

In 3 lists

Swagger-EZ

A tool geared towards pentesting APIs using OpenAPI definitions.

TnT-Fuzzer

OpenAPI 2.0 (Swagger) fuzzer written in python. Basically TnT for your API.

wadl-dumper

Dump all available paths and/or endpoints on WADL file.

In 2 lists

WuppieFuzz

WuppieFuzz is a coverage-guided REST API fuzzer developed on top of LibAFL, targeting a wide audience of end-users, with a strong focus on ease-of-use, explainability of the discovered flaws and modularity. WuppieFuzz supports all three settings of testing (black box, grey box and white box).

In 2 lists

Wsdler

WSDL Parser extension for Burp.

wsdl-wizard

WSDL Wizard is a Burp Suite plugin written in Python to detect current and discover new WSDL (Web Service Definition Language) files.

dredd

Language-agnostic HTTP API Testing Tool

In 2 lists

getallurls (gau)

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

In 7 listsDetails

SoapUI

SoapUI is a free and open-source cross-platform functional testing solution for APIs and web services.

In 2 lists

Step CI

Open-source framework for API Quality Assurance, which tests REST, GraphQL and gRPC automated and from Open API spec.

In 5 listsDetails

unfurl

Pull out bits of URLs provided on stdin

In 2 lists

noir

Noir is an attack surface detector form source code.

See category
92

Awesome Docker

veggiemonk/awesome-docker

:whale: A curated list of Docker resources and projects

Fresh★ 37k389 entriesPushed 18 days ago
92

Awesome GraphQL

chentsulin/awesome-graphql

Awesome list of GraphQL

Fresh★ 15k483 entriesPushed yesterday
91

Awesome-Kubernetes

ramitsurana/awesome-kubernetes

A curated list for awesome kubernetes sources :ship::tada:

Fresh★ 16k47 entriesPushed 8 days ago
91

Awesome Quant

wilsonfreitas/awesome-quant

A curated list of insanely awesome libraries, packages and resources for Quants (Quantitative Finance)

Fresh★ 30k678 entriesPushed today
89

Awesome Django

wsvincent/awesome-django

A curated list of awesome things related to Django

Fresh★ 11k326 entriesPushed 13 days ago
89

Awesome Terraform

shuaibiyy/awesome-tf

Curated list of resources on HashiCorp's Terraform and OpenTofu

Fresh★ 6.6k472 entriesPushed 2 days ago