Learn the API Top 10 by breaking it

DVAPI turns the OWASP API Security Top 10 for 2023 into ten hands-on challenges. Clone it, run it locally, and work through every risk from BOLA to unsafe consumption of APIs.
Person holding a smartphone displaying Bugbazaar app menu while sitting at a desk with an open laptop showing a Payatu security findings dashboard. The desk also has a spiral calendar, an open notebook with a pen, and a lamp.Person's hand resting on a laptop keyboard showing a dark-themed Swagger API documentation page for DVAPI, an intentionally vulnerable API, with endpoints for user registration and login visible.
Person using a laptop showing the Swagger interface for the DVAPI API, displaying endpoints for user registration and login, with the hand resting on the keyboard.
Meet dvapi

The vulnerability catalog

Every flaw in DVAPI is one of the OWASP API Security Top 10. Learn it here, and you will recognise it in the wild.
Outline of a shield with a curved connected line, a red dot on the bottom left, and a black checkmark inside the shield shape on the right.

Safe to attack

DVAPI runs on your own machine at 127.0.0.1, so nothing real is harmed and nothing is off-limits.
Abstract icon with a black curved line forming a shape resembling a shield or lock with a red dot in the center and two smaller black dots on a light pink background.

The real Top 10, not toy puzzles

Every challenge maps to a risk in the OWASP API Security Top 10 for 2023.
A black flagpole with a wavy flag outline and an upward pointing arrow with a red dot above the arrow's tip.

Flags mark your progress

Each challenge you crack yields a flag you submit in the app, so you can see how many of the ten you have cleared.
YOUR FIRST FLAG

How one challenge works, start to flag.

Challenge one is Broken Object Level Authorization, OWASP's number one API risk. Here is how you capture its flag.

01

You get an endpoint
The app gives you an API that returns your own records. The question it poses: can you read someone else's?

02

You change the ID
You request your own object, then swap the identifier for one that is not yours.

03

It just works
The API never checks whether the object belongs to you. That missing check is the bug: Broken Object Level Authorization.

04

You capture the flag
A successful exploit returns a flag string. Submit it in the app, and challenge one is done.
DVAPI documentation page showing API endpoints for notes and challenges with HTTP methods POST and GET, an input for server URL set to http://localhost:3000, and an authorize button.
The road ahead

The vulnerability catalog

50+ modules span every major mobile vulnerability class, beginner to advanced. Here are three the full set ships in the app.
Auth

Broken Object Level Authorization

API 1
Auth

 Broken Authentication

API 2
Auth

Broken Object Property Level Authorization

API 3
Auth

Unrestricted Resource Consumption

API 4
Auth

Broken Function Level Authorization

API 5
where it takes you

Ten flags later, you get it.

Reading the OWASP API Top 10 gives you the names. Exploiting all ten in DVAPI turns them into something you can spot in a real API. That is the point of the lab: the list becomes a skill.
Dashboard interface for DVAPI with a sidebar menu showing Challenges, Scoreboard, and API Swagger; main content titled Progress displaying six API challenge cards focused on authorization, authentication, resource consumption, and access controls, each with a short description, Read More link, flag option, and a blue Submit button.
Get set up

Follow the steps below

DVAPI runs locally in Docker. Clone the repo, bring it up, open it in your browser, and you are on challenge one.

Docker

Recommend
01
Clone the repo.
git clone github.com/payatu/DVAPI
02
Spin it up. 
 docker compose up -build
03
Open the app at 
127.0.0.1:3000
04
Point your tools. Hit it with 
curl

Manual

Without Docker
01
Install dependencies from the repo README.
02
Run the API server and confirm it responds.
03
Open the flag-submission panel in your browser.
04
Start with API1 (BOLA) to confirm everything works.
Lowercase letter i in red circle, symbol for information.
DVAPI is intentionally vulnerable. Run it locally in an isolated environment, and never expose it to the public internet.
FAQ

Questions Web Application teams ask us.

What is Web Security Testing?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
What vulnerabilities are tested during a Web Security Assessment?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
How is Web Security Testing different from a vulnerability scan?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
When should we perform Web Security Testing?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
What do we receive after the Web Security Assessment?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.
Can Web Security Testing identify business logic vulnerabilities?
Web Security Testing identifies vulnerabilities in web applications that attackers could exploit, helping organizations protect sensitive data and prevent security breaches.