API Security Insights and Resources

Stay informed with expert articles, guides, and the latest trends in API security


How to Automate API Discovery with Extensions

APIsec blog article cover image
Dan Barahona

What Is an API Call?

APIsec blog article cover image
Dan Barahona

Build Your API Inventory Automatically as You Browse

APIsec blog article cover image
Dan Barahona

OAuth 2.0 Common Security Flaws and Prevention Techniques

APIsec blog article cover image
Dan Barahona

Open Source vs Commercial API Security Scanners Compared

APIsec blog article cover image
Dan Barahona

Financial Services API Security Compliance Guide

APIsec blog article cover image
Dan Barahona

API Abuse Detection: Distinguishing Between Bots

APIsec blog article cover image
Dan Barahona

GraphQL Security Testing: Complete Guide for Developers

APIsec blog article cover image
Dan Barahona

Unrestricted Business Flows: OWASP Principle 6 Explained

APIsec blog article cover image
Dan Barahona

Instagram API Breach: Lessons on Sensitive Business Flows

APIsec blog article cover image
Dan Barahona

BFLA Explained: Securing API Functions from Abuse

APIsec blog article cover image
Dan Barahona

BOPLA Explained: Prevent Mass Assignment & Data Exposure

APIsec blog article cover image
Dan Barahona

Preventing Resource Abuse: Protect APIs from Harvesting

APIsec blog article cover image
Dan Barahona

Inside the Peloton Breach: Broken Authentication Lessons

APIsec blog article cover image
Dan Barahona

Improper Inventory Management in APIs: OWASP 9 Explained

APIsec blog article cover image
Dan Barahona

Unsafe API Consumption: Securing Third-Party Integrations

APIsec blog article cover image
Dan Barahona

Broken Authentication Explained: OWASP API Principle 2

APIsec blog article cover image
Dan Barahona

Are Free API Scanners Actually Worth It?

APIsec blog article cover image
Dan Barahona

How to Choose the Right API Pen-Testing Tool

APIsec blog article cover image
Dan Barahona

BOLA Explained: OWASP API Security Principle 1 for Teams

APIsec blog article cover image
Dan Barahona

AppSec Tech Landscape: Strengths, Gaps & What Teams Need

APIsec blog article cover image
Dan Barahona

The Three Pillars of Modern API Security

APIsec blog article cover image
Dan Barahona

API Failure: 7 Causes and How to Fix Them

APIsec blog article cover image
Dan Barahona

Which API Security Testing Tool Should I Choose

APIsec blog article cover image
Dan Barahona

CI/CD API Security: A Complete Automation Guide

APIsec blog article cover image
Dan Barahona

API Security Mistakes That Lead to Data Breaches

APIsec blog article cover image
Dan Barahona

How to Detect Business Logic Vulnerabilities in API

APIsec blog article cover image
Dan Barahona

Why Do APIs Keep Getting Hacked

APIsec blog article cover image
Dan Barahona

API Fuzzing for Security Testing: Complete Guide

APIsec blog article cover image
Dan Barahona

Difference Between SAST and DAST: Key Insights & Tools

APIsec blog article cover image
Dan Barahona

BOLA Explained: The Threat No One’s Testing

APIsec blog article cover image
Jesse Freeman

APIsec presents the 2024 API Security Market Report

APIsec blog article cover image
Shelby Matthews

Internal APIs at Risk: Why Testing Matters

APIsec blog article cover image
Stacey Levine

2024 API Security Best Practices

APIsec blog article cover image
Dan Barahona

Upcoming DSS 4.0 Deadline for PCI Compliance

APIsec blog article cover image
Shelby Matthews

Edulog API Breach Explained: BOLA Risks & Fixes

APIsec blog article cover image
Shelby Matthews

2023 OWASP API Top Ten

APIsec blog article cover image
Shelby Matthews

HIPAA vs Cures Act: Navigating Privacy & Interoperability

APIsec blog article cover image
Christine Bevilacqua

How to Choose an API Security Tech Stack

APIsec blog article cover image
Dan Barahona

Top 5 Burp Suite Alternatives for API Security Testing

APIsec blog article cover image
Dan Barahona

Burp vs ZAP: Which Finds More API Bugs?

APIsec blog article cover image
Dan Barahona

Best Pen-Testing Tools for Modern APIs

APIsec blog article cover image
Dan Barahona

API Testing Automation: How It Transforms DevSecOps

APIsec blog article cover image
Dan Barahona

Shift Left Security: The Ultimate Guide

APIsec blog article cover image
Dan Barahona

Business Logic Flaws in APIs: The Silent Threat

APIsec blog article cover image
Dan Barahona

HTTP Verb Tampering: Key Risks and Fixes

APIsec blog article cover image
Wesley Meier

How to Generate OpenAPI (OAS) Specs for REST APIs

APIsec blog article cover image
Dave Piskai

Business Logic vs Application Logic in APIs

APIsec blog article cover image
Wesley Meier

What Is a Business Logic Layer?

APIsec blog article cover image
Dan Barahona

Fintech API Security Checklist: Avoid Disaster

APIsec blog article cover image
Dan Barahona

Banking APIs: Closing the Door on Fraud

APIsec blog article cover image
Dan Barahona

Fintech APIs: Are You Leaking Money and Data?

APIsec blog article cover image
Dan Barahona

What Is OAuth 2.0 and How Does It Work?

APIsec blog article cover image
Dan Barahona

Top API Security Testing Tools You Need Now

APIsec blog article cover image
Dan Barahona

API Security Checklist: What You Need To Know

APIsec blog article cover image
Dan Barahona

Excessive Data Exposure: Are Your APIs Over-Sharing?

APIsec blog article cover image
Dan Barahona

3 Steps for an Effective API Testing Process

APIsec blog article cover image
Dan Barahona