Tutorials

API Security & Conformance Scan using OpenAPI Swagger Editor Extension in VS Code

A dynamic security scan of your API to check for conformance against the API design (OpenAPI contract) and security vulnerabilities such as BOLA and BFLA. The tutorial videos below are relevant for all the available IDEs. API Scan is also available on the 42Crunch Platform and CI/CD platforms such as GitHub Actions and Azure DevOps.

Activate API Scan

You can run the dynamic API Scan security test locally on your machine without having to share the API. Activation differs slightly between free and paying customers. Please refer to the relevant video below.

Paying Customers

Free Customers

Overview of the Scan Configuration Viewer

Explanation of the scan configuration viewer where you configure and run your scan tests

Running your first API Scan

Learn how to configure and run your first API Scan and read the results

Use Variable Substitution

Variable substitution is a powerful feature that enables dynamic changes to your requests and responses

Setup Dynamic API Authentication

Authentication tokens such as OAuth or an API key may be required In order to test your API. Find out how to configure the scan for dynamic authentication.

API Happy Path "Scanarios"

You can add additional operations and requests to your scan configuration scenario to create more complex test scenarios. Take a look at the video explainer.

Setup and Teardown using Global Blocks

Set up and tear down test resources or create test states to test the API using before and after blocks e.g. Create a new test user account, run tests and then delete the new user

Test for Broken Authorization

Find out how to test your APIs for Authorization vulnerabilities such as OWASP API 01:2023 - Broken Object Level Authorization (BOLA) or OWASP API 05:2023 - Broken Functional Level Authorization (BFLA) using the 42Crunch API Scan tool.

Latest Resources

WEBINAR

OWASP BOLA, BA, BOPLA: wie man sie finded und behebt

Wir werden verstehen wie die OWASP API Top 3 von Hackern genutzt werden um Daten aus Unternehmen zu stehlen und wie man sie schon während der Implementierung findet und beheben kann.

BLOG

Why FAPI 2.0 alone is not enough medicine to secure healthcare APIs

By Jacques Declas | August 18, 2025

In conversation recently with Mark Ballard of ComputerWeekly I discussed the significant announcement by the Norwegian Health Network (NHN), that  it has mandated FAPI 2.0 (Financial-grade API) across its entire healthcare ecosystem, including hospitals, clinics, pharmacies, and municipal health services.  The FAPI 2.0  Security Profile is an API security […]

DataSheet

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Secure Your APIs Today

#1 API security platform