Resource / Blogs /

Beginner’s Guide to RESTful API VAPT – Part 1

A beginner-friendly introduction to RESTful APIs, HTTP methods, response codes, and the core concepts needed before performing REST API VAPT.
By
Siddharth-Bezalwar
July 7, 2017
7 mins
Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.

Key Takeaways

  • REST stands for Representational State Transfer and defines an architectural style for web services.
  • RESTful systems follow constraints such as statelessness, cacheability, uniform interfaces, and client-server separation.
  • REST APIs expose resources through URIs and allow clients to interact with them using HTTP methods.
  • GET, POST, PUT, PATCH, DELETE, and HEAD are commonly used to perform operations on API resources.
  • HTTP status codes such as 200, 201, 400, 401, 403, 404, 405, 409, and 500 communicate the result of API requests.
  • Understanding normal API request-response behavior provides the foundation required before moving into REST API vulnerability assessment and penetration testing (VAPT).

With more and more web applications are developed on top of the web services (RESTful API) many web application penetration tester are wondering exactly how to test these web services and what to actually look for. To help explain how to perform VAPT of REST API, let’s take a quick look at the basics of RESTful API.

What is a RESTful API?

Before understanding RESTful API let’s take a look at what the term REST actually mean.

REST

REST stands for REpresentational State Transfer which is a style of web architecture which describes six constraints.

Uniform Interface

Uniform interface simplifies and decouples the architecture, which enables to each part to develop independently. There are four basic principles for designing uniform interface.

  1. Resource Based – Individual resources are identified in requests using URIs as resource identifiers.
  2. Resource Manipulations Through Representations – A client with a representation of a resource along with its metadata can modify or delete the resource on the server depending on the permissions.
  3. Self-descriptive Messages – Each message contains information to describe how to process the message.
  4. Hypermedia as the Engine of Application State (HATEOAS) – Clients provide state via body contents, query-string parameters, request headers and the requested URI (the resource name). Services provide state to clients via body content, response codes, and response headers.

Stateless

– No client context should be stored on the server between requests. This means required the state to handle the request is provided within the request as a part of the URI, query-string parameters, request body, or HTTP header.

Cacheable

Responses must implicitly or explicitly specify themselves as cacheable, or not.

Client/Server

Client and server must be separated via a uniform interface.

Layered

A client cannot tell whether it is connected directly to the end server, or to an intermediary along the way.

Code on Demand

Servers are able to temporarily customize the functionality of a client by transferring logic to it that it can execute by using JavaScript, JAVA applets, etc.

Complying with these constraints is referred as RESTful. After understanding REST let’s take a look at RESTful Web Services API.

RESTful Web Services (API)

“Representational state transfer (REST) or RESTful web services is a way of providing interoperability between computer systems on the Internet. REST-compliant Web services allow requesting systems to access and manipulate textual representations of Web resources using a uniform and predefined set of stateless operations” – Wikipedia

Web services are implemented using HTTP and the principles of REST. It is a collection of resources with four aspects – base URI of the web service, content type supported by web service, operations supported by web service and API must be hypertext driven.

Aspects of RESTful API

A RESTful API client does not need to know details about the structure of API. It is server’s responsibility to provide necessary information the client needs to interact with the service. The client can interact with APIs with the HTTP methods. Let’s look at different HTTP methods used by the client to interact with APIs.

HTTP Methods for RESTful API

HTTP response codes are used to indicate the status of an operation requested by client.

Response Status – HTTP Response Codes

Following are primary or most-commonly-used HTTP response code
200 OK
Indicates the success of requested operation.
201 CREATED
Indicates successful creation of entity via either POST or PUT.
204 NO CONTENT
Indicates success but nothing is in the response body, generally used for DELETE and PUT operations.
400 BAD REQUEST
Indicates general error occurred at the server while serving request which resulted in an invalid state. Reasons for such errors are validation error, missing required parameters, etc.
401 UNAUTHORIZED
Indicates error code response for missing or invalid authentication token.
403 FORBIDDEN
Indicates error code for when the user is not authorized to perform the operation or the resource is unavailable for some reason (e.g. time constraints, etc.).
404 NOT FOUND
Indicates when the requested resource is not found, whether it doesn’t exist or if there was a 401 or 403 that, for security reasons, the service wants to mask.
405 METHOD NOT ALLOWED
Indicates that the requested URL exists, but the requested HTTP method is not applicable.
409 CONFLICT
Indicates a resource conflict occurred. For example, trying to create two users with same information.
500 INTERNAL SERVER ERROR
Indicates the error which cannot be addressed from the consumer end.
To get a clear picture here is sample request to API end point.

Request to API end point

And it’s response.

Response from API end point

Continue to VAPT part

Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.
Author
Siddharth-Bezalwar
Ex-Bandit
Red arrow pointing diagonally upward to the right.Red arrow pointing diagonally upward to the right.
FAQ

Questions Web Application teams ask us.

What is a RESTful API?
A RESTful API is a web service designed according to REST architectural principles, allowing clients to access and manipulate resources using standard HTTP operations.
What are the main constraints of REST architecture?
REST defines six constraints: Uniform Interface, Statelessness, Cacheability, Client-Server separation, Layered System, and Code on Demand.
Which HTTP methods are commonly used in REST APIs?
Common methods include GET for retrieving resources, POST for creating resources, PUT and PATCH for updating resources, DELETE for removing resources, and HEAD for retrieving headers.
What is the difference between HTTP 401 and 403 responses?
A 401 Unauthorized response generally indicates missing or invalid authentication, while 403 Forbidden means the user is authenticated but does not have permission to perform the requested operation.
Why should penetration testers understand REST fundamentals before testing APIs?
Understanding REST resources, HTTP methods, request structures, response codes, and stateless communication helps testers understand how an API behaves before performing security testing.

Keep Reading

For Security Leaders
Agentic AI Security: The Hidden Attack Surface Beyond Prompt Injection
August 25, 2026
10 min
For Security Leaders
Research & disclosures
Binwalk Path Traversal Vulnerability: Turning Firmware Analysis into Code Execution
August 26, 2026
8 min
Guides & tutorials
For Security Leaders
An Introduction to Smali
August 26, 2026
8 min
Dark scene with vertical thin orange lines resembling distant illuminated bars or streaks against a black background and a faint horizontal red glow near the bottom.