Lab · api
crAPI
Completely Ridiculous API — intentionally vulnerable microservice API (vehicle-owner theme) built around the OWASP API Security Top 10 (BOLA/BFLA/mass assignment).
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsapi
More labs & practice targets
- Damn Vulnerable C# Application (API)apiDeliberately vulnerable C#/.NET API-only application for learning and practicing API security.
- Damn Vulnerable RESTaurantapiStateful FastAPI game teaching privilege escalation and long-horizon API workflows with attack/fix modes.
- DVWS-nodeapiDamn Vulnerable Web Services (Node) — app with a web service and API covering IDOR, mass assignment, NoSQL/SQLi, SSRF, JWT and XXE.
- Generic UniversityapiVulnerable Laravel API (student-grades theme) aligned to the OWASP API Security Top 10; bugs are visible, not hidden.
- OWASP crAPIapiRealistic microservices app for advanced API testing: multi-user authorization, API chaining, and business workflows.
- PixiapiOWASP DevSlop MEAN-stack app with deliberately insecure APIs for scanning and API-security demos.