Built in the trenches—this repository captures real-world API security insights, attack techniques, and practical penetration testing workflows.
-
Updated
Aug 3, 2026
Built in the trenches—this repository captures real-world API security insights, attack techniques, and practical penetration testing workflows.
A modern, deliberately-vulnerable, API-first web app - a DVWA alternative covering the OWASP API Security Top 10 (2023) and Web Top 10 (2021). Two distinct origins (Next.js 14 + FastAPI) with a cookie-to-Bearer JWT bridge and 45+ catalogued vulns, each paired with a secured twin. Local, educational use only.
Add a description, image, and links to the owasp-api-security-top-10 topic page so that developers can more easily learn about it.
To associate your repository with the owasp-api-security-top-10 topic, visit your repo's landing page and select "manage topics."