You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This project is designed to address the ever-increasing number of organizations
that are deploying potentially sensitive APIs as part of their software
offerings. These APIs are used for internal tasks and to interface with third
parties. Unfortunately, many APIs do not undergo the rigorous security testing
that would help make them secure from an attack.
The OWASP API Security Project seeks to provide value to software developers and
security assessors by underscoring the potential risks in insecure APIs, and
illustrating how these risks may be mitigated. In order to facilitate this goal,
the OWASP API Security Project will create and maintain a Top 10 API Security
Risks document, as well as a documentation portal for best practices when
creating or assessing APIs.
Description
While working as developers or information security consultants, many people
have encountered APIs as part of a project. While there are some resources to
help create and evaluate these projects (such as the OWASP REST Security Cheat
Sheet), there has not be a comprehensive security project designed to assist
builders, breakers, and defenders in the community.
This project aims to:
Create the OWASP Top Ten API Security Risks document, which can easily
underscore the most common risks in the area.
Create a documentation portal for developers to build APIs in a secure manner.
Work closely with the security community to maintain living documents that
evolve with security trends.
The OWASP API Security Project documents are free to use!
The OWASP API Security Project is licensed under the Creative Commons
Attribution-ShareAlike 4.0 license, so you can copy, distribute, and
transmit the work. You can also adapt it, and use it commercially, as long as
you attribute the work. If you alter, transform, or build upon this work, you
may distribute the resulting work only under the same or similar license to this
one.