![](/assets/headers/header-logo.png)

![](https://img.shields.io/badge/Tools%20%26%20Resources%20Available-24-757575?style=for-the-badge)

### Documentation

* [MindAPI](https://github.com/dsopas/MindAPI) - Organize your API security assessment by using MindAPI. ![GitHub last commit](https://img.shields.io/github/last-commit/dsopas/MindAPI?style=flat)

### Manipulation & Testing

* [Arjun](https://github.com/s0md3v/Arjun) - HTTP parameter discovery suite. ![GitHub last commit](https://img.shields.io/github/last-commit/s0md3v/Arjun?style=flat)
* [Astra](https://github.com/flipkart-incubator/Astra) - Automated Security Testing For REST API's. ![GitHub last commit](https://img.shields.io/github/last-commit/flipkart-incubator/Astra?style=flat)
* [Apache JMeter](https://jmeter.apache.org/download_jmeter.cgi) - Java application designed to load test functional behavior and measure performance.
* [Automatic API Attack Tool](https://github.com/imperva/automatic-api-attack-tool) - Imperva's API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output. ![GitHub last commit](https://img.shields.io/github/last-commit/imperva/automatic-api-attack-tool?style=flat)
* [Burp Suite](https://portswigger.net/burp) - Arm yourself with the leading toolkit for web security testing. Test, find, and exploit vulnerabilities. 
* [Fiddler Everwhere](https://www.telerik.com/fiddler/fiddler-everywhere) - A web debugging proxy for macOS, Windows, and Linux. Capture, inspect, monitor all HTTP(S) traffic between your computer and the Internet, mock requests, and diagnose network issue. 
* [Hoppscotch](https://github.com/hoppscotch/hoppscotch) - Open source tool that covers the entire testing spectrum (functional, security, load, mocking). ![GitHub last commit](https://img.shields.io/github/last-commit/hoppscotch/hoppscotch?style=flat)
* [HttpMaster](https://www.httpmaster.net/) - Master HTTP testing & debugging.
* [Insomnia](https://insomnia.rest/) - Quickly and easily send REST, SOAP, GraphQL, and GRPC requests directly within Insomnia. ![GitHub last commit](https://img.shields.io/github/last-commit/Kong/insomnia?style=flat)
* [Karate](https://github.com/intuit/karate) - Test automation made simple. ![GitHub last commit](https://img.shields.io/github/last-commit/intuit/karate?style=flat) 
* [Kiterunner](https://github.com/assetnote/kiterunner) - Contextual Content Discovery Tool. ![GitHub last commit](https://img.shields.io/github/last-commit/assetnote/kiterunner?style=flat)
* [Postman](https://www.postman.com/) - A collaboration platform for API development. Postman's features simplify each step of building an API and streamline collaboration so you can create better APIs—faster. 
* [SoapUI](https://www.soapui.org/tools/soapui/) - Open source tool that covers the entire testing spectrum (functional, security, load, mocking).
* [Taurus](https://gettaurus.org/) - Taurus improves experience of JMeter, Selenium and others.
* [Test Mace](https://testmace.com/) - A modern powerful crossplatform tool for working with an API and creating automated API tests. 
* [vRESTng](https://vrest.io) - Automate API Requests as Runnable Test Cases, just by providing Request Details. Also, Validate API Responses using Test Case Assertions.

### Training

* [crAPI](https://github.com/OWASP/crAPI) - Completely ridiculous API (crAPI). ![GitHub last commit](https://img.shields.io/github/last-commit/OWASP/crAPI?style=flat)
* [Damn Vulnerable GraphQL App](https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application) - An intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security. ![GitHub last commit](https://img.shields.io/github/last-commit/dolevf/Damn-Vulnerable-GraphQL-Application?style=flat)
* [DVMS](https://github.com/ne0z/DamnVulnerableMicroServices) - This is vulnerable microservice written in many language to demonstrating OWASP API Top Security Risk. ![GitHub last commit](https://img.shields.io/github/last-commit/ne0z/DamnVulnerableMicroServices?style=flat)
* [dvws-node](https://github.com/snoopysecurity/dvws-node) - Damn Vulnerable Web Service is a vulnerable web service/API/application that can be used to learn webservices/API vulnerabilities. ![GitHub last commit](https://img.shields.io/github/last-commit/snoopysecurity/dvws-node?style=flat) 
* [Kontra](https://application.security/free/owasp-top-10-API) - A series of free interactive application security training modules that teach developers how to identify and mitigate security vulnerabilities in their web API endpoints.
* [VAmPI](https://github.com/erev0s/VAmPI) - Vulnerable REST API with OWASP top 10 vulnerabilities for APIs. ![GitHub last commit](https://img.shields.io/github/last-commit/erev0s/VAmPI?style=flat)
* [vAPI](https://github.com/roottusk/vapi) - Vulnerable Adversely Programmed Interface which is Self-Hostable PHP Interface that mimics OWASP API Top 10 scenarios in the means of Exercises. ![GitHub last commit](https://img.shields.io/github/last-commit/roottusk/vapi?style=flat)
