Skip to main content

Awesome API Security: A Curated Collection of Resources for Bulletproof API Protection!

63
GitHub Stars
103
Curated Resources
12
Categories
21 hours ago
Last Refreshed
🎳 OWASP API Top 10 2023📚 Books🔐 Vulnerable APIs📝 Cheatsheets✅ Checklists🎥 Playlists🏗 Specifications🎙 Podcast🗂 Wikis & Collections🗺 Mind Maps📜 Newseltters⚙ Projects

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me 🔐 vulnerable apis resources from awesome-api-security-essentials"

Installation instructions →

What's inside

🔐 Vulnerable APIs

  • 1

    A vulnerable API designed for learning API security practices

  • 10

    A Node.js/Express app with security vulnerabilities

  • 11

    A modern, vulnerable e-commerce web app

  • 12

    A vulnerable e-commerce web app for security training

  • 13

    A vulnerable Android app with insecure APIs

  • 14

    A vulnerable Java web app for learning application security

📚 Books

🎳 OWASP API Top 10 2023

📝 Cheatsheets

🏗 Specifications

  • API Blueprint

    A high-level API design language for describing and designing APIs.

  • GraphQL

    A query language for APIs and a runtime for executing queries against your data.

  • HAL (Hypertext Application Language)

    A standard for describing RESTful APIs using hypermedia.

  • JSON:API

    A specification for building APIs in JSON.

  • JSON Web Tokens (JWT)

    A compact, URL-safe means of representing claims to be transferred between parties.

  • OAuth 2.0

    A widely-adopted authorization framework for securing API access.

✅ Checklists

📜 Newseltters

  • API Evangelist

    A blog and newsletter by Kin Lane that covers various API topics, including security.

  • Secjuice

    A cybersecurity publication with a dedicated section for API security articles. Subscribe to their newsletter for updates.

  • Security Weekly

    A cybersecurity podcast network and newsletter that occasionally covers API security topics.

  • StatusCode Weekly

    A weekly newsletter that covers web operations and occasionally includes API security articles.

  • The Hacker New

    A blog and newsletter that covers various API topics, including security.

  • The New Stack

    A platform for news and analysis on various technology topics, including API security. Subscribe to their newsletter for regular updates.

🗺 Mind Maps

Showing a sample of 103 resources. View the full list on GitHub →