0 of 0 steps completed

Ten phases, from API fundamentals to high-impact chaining and exam prep. Each step has a checkbox and a list of resources. Tick steps as you finish them. Progress is saved in this browser. Phases 3, 5, and 6 carry most of the bounty value, so spend the most time there.

Phase 1: API Fundamentals

Step 1.1 What APIs are and how they work
Step 1.2 REST, GraphQL, gRPC, and SOAP
Step 1.3 API documentation and discovery

Phase 2: API Recon and Enumeration

Step 2.1 Passive and active API recon
Step 2.2 Hidden endpoints and parameter discovery
Step 2.3 Versioning and deprecated endpoints

Phase 3: Authentication and Authorization

Step 3.1 Broken authentication (API2:2023)
Step 3.2 Broken Object Level Authorization (BOLA / API1:2023)
Step 3.3 Mass assignment (API3:2023)
Step 3.4 JWT and OAuth attacks

Phase 4: Injection and Business Logic

Step 4.1 SQL injection in APIs
Step 4.2 NoSQL injection in APIs
Step 4.3 SSRF in APIs
Step 4.4 Command injection and SSTI in APIs
Step 4.5 Rate limit and resource consumption (API4:2023)

Phase 5: GraphQL and Modern Stacks

Step 5.1 GraphQL fundamentals and introspection
Step 5.2 GraphQL attacks
Step 5.3 WebSockets and gRPC

Phase 6: Chaining for High Impact

Step 6.1 Chaining API bugs
Step 6.2 High-impact company targets
Step 6.3 Real-world API bug bounty writeups

Phase 7: Tools and Programming

Step 7.1 API testing tools
Step 7.2 Python for API testing
Step 7.3 API security scanning

Phase 8: Books, Podcasts, and Videos

Step 8.1 Essential API security books
  • BookHacking APIs, Corey J. Ball (No Starch Press)
  • BookAPI Security in Action, Neil Madden (Manning)
  • BookOAuth 2.0 in Action, Richer and Sanso (Manning)
Step 8.2 Podcasts
Step 8.3 YouTube playlists and channels

Phase 9: Labs and Practice

Step 9.1 HTB Academy and machines
Step 9.2 PortSwigger Web Security Academy
Step 9.3 CTF and bug bounty practice

Phase 10: Exam Preparation and Career

Step 10.1 CWES and CWEE API topics
Step 10.2 API security training