API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven templates
-
Updated
Aug 2, 2026 - Go
API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven templates
Built in the trenches—this repository captures real-world API security insights, attack techniques, and practical penetration testing workflows.
Professional API security auditing tool that detects rate limiting vulnerabilities and misconfigurations in REST APIs
Defensive API security testing templates for Postman and Newman, with OWASP-aligned collections, safe payloads, CI/CD automation, and vulnerable local labs.
Production-style API security observability lab with Kong Gateway, Flask, Prometheus, Loki, Grafana, active attack blocking, OWASP API validation, SOC dashboards, and compliance evidence.
Secure healthcare API security demo in .NET 10 demonstrating JWT authentication, RBAC, audit logging, HIPAA-inspired access controls, secure middleware, and OWASP API Security concepts.
API-to-OT attack detection lab: crAPI + Conpot ICS honeypot + Grafana/Loki on Proxmox. Demonstrates BOLA, broken auth, and SSRF-to-OT pivot detection.
Add a description, image, and links to the owasp-api-security topic page so that developers can more easily learn about it.
To associate your repository with the owasp-api-security topic, visit your repo's landing page and select "manage topics."