API Security Mastery Roadmap: REST, GraphQL, BOLA, and Chaining
0 of 0 steps completed
Ten phases, from API fundamentals to high-impact chaining and exam prep. Each step has a checkbox and a list of resources. Tick steps as you finish them. Progress is saved in this browser. Phases 3, 5, and 6 carry most of the bounty value, so spend the most time there.
Phase 1: API Fundamentals
Step 1.1 What APIs are and how they work
- BookHacking APIs, Chapters 1 to 3, Corey J. Ball (No Starch Press)
- BookAPI Security in Action, Chapters 1 to 3, Neil Madden (Manning)
- HTB AcademyWeb Service and API Attacks
- PortSwiggerAPI testing learning path
- DocOWASP API Security Top 10 (2023)
- YouTubeInsiderPhD, Everything API Hacking
Step 1.2 REST, GraphQL, gRPC, and SOAP
- BookHacking APIs, Chapters 4 to 6, Corey J. Ball
- PortSwiggerAPI testing labs, GraphQL labs
- HTB AcademyAttacking GraphQL
- GitHubarainho/awesome-api-security
Step 1.3 API documentation and discovery
- BookHacking APIs, Chapter 7 (API Documentation and Discovery)
- PortSwiggerExploiting an API endpoint using documentation
- ToolPostman, Swagger UI, and OpenAPI spec parsing
- GitHubawesome-api-security, discovery tooling list
Phase 2: API Recon and Enumeration
Step 2.1 Passive and active API recon
- BookHacking APIs, Chapter 8 (API Reconnaissance)
- HTB AcademyWeb Service and API Attacks, recon section
- GitHubKathanP19/HowToHunt, API methodology
- Toolffuf for endpoint fuzzing, Burp Suite, Postman
Step 2.2 Hidden endpoints and parameter discovery
- PortSwiggerFinding and exploiting an unused API endpoint
- ToolArjun, ParamSpider for parameter discovery
- PayloadsPayloadsAllTheThings, API notes
Step 2.3 Versioning and deprecated endpoints
- PortSwiggerTesting API versions and deprecated routes
- HackerOneHacktivity, API version bypass reports
- ToolArjun for hidden parameters on old versions
Phase 3: Authentication and Authorization
Step 3.1 Broken authentication (API2:2023)
- BookHacking APIs, Chapters 9 to 10, Corey J. Ball
- PortSwiggerAuthentication labs, JWT labs
- HackerOneReport 2056630, authentication bypass
- Tooljwt_tool, Burp Suite Autorize
Step 3.2 Broken Object Level Authorization (BOLA / API1:2023)
- BookHacking APIs, Chapter 11 (BOLA)
- PortSwiggerAccess control and IDOR labs
- HackerOneReport 111014, IDOR
- HackerOneReport 2268239, IDOR
- ToolBurp Suite Autorize for automated BOLA checks
Step 3.3 Mass assignment (API3:2023)
- BookHacking APIs, Chapter 12 (Mass Assignment)
- PortSwiggerExploiting a mass assignment vulnerability
- DocOWASP Mass Assignment Cheat Sheet
Step 3.4 JWT and OAuth attacks
- BookAPI Security in Action, JWT and OAuth chapters, Neil Madden
- PortSwiggerJWT labs, OAuth labs
- GitHubticarpi/jwt_tool
- HackerOneHacktivity, OAuth redirect_uri bypass reports
Phase 4: Injection and Business Logic
Step 4.1 SQL injection in APIs
- PortSwiggerSQL injection labs
- HTB AcademySQL Injection Fundamentals
- Toolsqlmap, JSON and request templates
Step 4.2 NoSQL injection in APIs
- PortSwiggerNoSQL injection labs
- PayloadsPayloadsAllTheThings, NoSQL Injection
- HackTricksNoSQL Injection
Step 4.3 SSRF in APIs
- PortSwiggerSSRF labs
- HTB AcademyServer-side Attacks, SSRF section
- HackerOneReport 1809193, SSRF
- HackTricksSSRF, cloud metadata section
Step 4.4 Command injection and SSTI in APIs
- PortSwiggerOS command injection labs, SSTI labs
- HTB AcademyCommand Injections, Server-side Attacks
- PayloadsPayloadsAllTheThings, Command Injection and SSTI
Step 4.5 Rate limit and resource consumption (API4:2023)
- HackTricksRate limit bypass
- Toolfireprox, Burp Turbo Intruder for high-rate testing
- DocOWASP API4:2023 Unrestricted Resource Consumption
Phase 5: GraphQL and Modern Stacks
Step 5.1 GraphQL fundamentals and introspection
- BookHacking APIs, Chapter 13 (GraphQL)
- HTB AcademyAttacking GraphQL
- PortSwiggerGraphQL labs
- GitHubEscape-Technologies/awesome-graphql-security
- ToolInQL (Burp extension)
Step 5.2 GraphQL attacks
- PortSwiggerGraphQL labs (batching, alias abuse, injection)
- HackTricksGraphQL attacks
- HackerOneReport 1086878, GraphQL
Step 5.3 WebSockets and gRPC
- PortSwiggerWebSockets labs
- HTB AcademyWeb Service and API Attacks, WebSocket section
- DocOWASP WSTG, testing WebSockets
Phase 6: Chaining for High Impact
Step 6.1 Chaining API bugs
- GitHubKathanP19/HowToHunt, exploitation and impact
- HackerOneHacktivity, API to account takeover chains
- BlogStudy disclosed chains where a token or key exposure escalates to full access
Step 6.2 High-impact company targets
- ProgramShopify, Spotify, GitLab, Epic Games
- ProgramGoogle Bug Hunters, Meta Bug Bounty
- ProgramNetflix, Okta, and Tesla (check their current program pages for scope)
Step 6.3 Real-world API bug bounty writeups
Phase 7: Tools and Programming
Step 7.1 API testing tools
- ToolBurp Suite (Autorize, InQL), Postman, OWASP ZAP
- ToolNuclei, API templates
- Toolffuf, Arjun, ParamSpider
Step 7.2 Python for API testing
- Toolrequests, pytest, PyJWT, and jsonschema for test harnesses
- GitHubawesome-api-security, scripting and automation
- DocRequests documentation
Step 7.3 API security scanning
Phase 8: Books, Podcasts, and Videos
Step 8.1 Essential API security books
- BookHacking APIs, Corey J. Ball (No Starch Press)
- BookAPI Security in Action, Neil Madden (Manning)
- BookOAuth 2.0 in Action, Richer and Sanso (Manning)
Step 8.2 Podcasts
- PodcastCritical Thinking Bug Bounty Podcast (API episodes)
- PodcastDarknet Diaries
- PodcastThe Secure Developer, API security episode
Step 8.3 YouTube playlists and channels
- YouTubeInsiderPhD, Everything API Hacking
- YouTubeSTÖK, NahamSec
- YouTubePortSwigger, API and GraphQL labs
Phase 9: Labs and Practice
Step 9.1 HTB Academy and machines
- HTB AcademyWeb Service and API Attacks
- HTB AcademyAttacking GraphQL
- HTB MachineAPI-heavy web machines (check the retired machine list)
Step 9.2 PortSwigger Web Security Academy
- PortSwiggerAPI testing labs (all)
- PortSwiggerGraphQL labs (all)
- PortSwiggerAccess control, JWT, OAuth, and SSRF labs
Step 9.3 CTF and bug bounty practice
Phase 10: Exam Preparation and Career
Step 10.1 CWES and CWEE API topics
- HTB AcademyCWES path API modules
- HTB AcademyCWEE path advanced API and GraphQL
- PortSwiggerAPI labs as timed practice