# arainho/awesome-api-security

A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.

Repository: https://github.com/arainho/awesome-api-security
Canonical: https://ross.abutalabs.com/products/awesome-api-security
License: GPL-3.0
License Family: copyleft
Topics: api-security, api-sec, awesome-list, api-hacking, api-pentest, apisec, security, pentest, fuzzing, api-hacks, api-hunting, infosec, api-hardening
Archived: true
Last push: 2026-05-01T18:32:56+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 80, release rhythm 35, longevity 100
- inputs: {"age_days": 2210, "days_push": 124, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3862, forks 651 (observed 2026-08-28T04:08:27.544297+00:00)

## What it is
A curated awesome-list of API security tools and resources, emphasizing open-source projects. It covers API key discovery, fuzzing, scanning, firewalls, training labs, and deliberately vulnerable APIs.

## Use cases
- find open-source API security testing tools
- learn API penetration testing
- discover deliberately vulnerable APIs for practice
- find API fuzzing wordlists and seclists
- locate leaked API key validation tools
- find API security training and labs
- build an API security checklist

## When to choose
- you need a curated starting point for API security tooling
- you are learning API pentesting or bug bounty hunting
- you want open-source alternatives to commercial API security products

## When to avoid
- you need a runnable tool rather than a link collection
- you need commercial or vendor-supported API security solutions
- you need guaranteed up-to-date tool versions

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, penetration-testing, fuzzing, vulnerability-scanning
- domain: security, apis, penetration-testing, awesome-lists, developer-tools
- platform: cross-platform
- tags: awesome-list, api-security, api-pentest, curated-resources, infosec, bug-bounty

## Member repositories
- arainho/awesome-api-security (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:27.544297+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:25:53.431810+00:00, confidence not recorded.
  - readme: https://github.com/arainho/awesome-api-security (fetched 2026-08-28T04:08:27.544297+00:00, sha d80b2f303003)
- Data as of 2026-08-30T08:39:29.467469+00:00.
