Lab · api
Tiredful API
Intentionally broken Django REST API teaching information disclosure, IDOR, access control, throttling and injection flaws.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsapi
More labs & practice targets
- crAPIapiCompletely Ridiculous API — intentionally vulnerable microservice API (vehicle-owner theme) built around the OWASP API Security Top 10 (BOLA/BFLA/mass assignment).
- Damn Vulnerable C# Application (API)apiDeliberately vulnerable C#/.NET API-only application for learning and practicing API security.
- Damn Vulnerable RESTaurantapiStateful FastAPI game teaching privilege escalation and long-horizon API workflows with attack/fix modes.
- DVWS-nodeapiDamn Vulnerable Web Services (Node) — app with a web service and API covering IDOR, mass assignment, NoSQL/SQLi, SSRF, JWT and XXE.
- Generic UniversityapiVulnerable Laravel API (student-grades theme) aligned to the OWASP API Security Top 10; bugs are visible, not hidden.
- OWASP crAPIapiRealistic microservices app for advanced API testing: multi-user authorization, API chaining, and business workflows.