Tutorials

API Security & Conformance Scan using OpenAPI Swagger Editor Extension in VS Code

A dynamic security scan of your API to check for conformance against the API design (OpenAPI contract) and security vulnerabilities such as BOLA and BFLA. The tutorial videos below are relevant for all the available IDEs. API Scan is also available on the 42Crunch Platform and CI/CD platforms such as GitHub Actions and Azure DevOps.

Activate API Scan

You can run the dynamic API Scan security test locally on your machine without having to share the API. Activation differs slightly between free and paying customers. Please refer to the relevant video below.

Paying Customers

Free Customers

Overview of the Scan Configuration Viewer

Explanation of the scan configuration viewer where you configure and run your scan tests

Running your first API Scan

Learn how to configure and run your first API Scan and read the results

Use Variable Substitution

Variable substitution is a powerful feature that enables dynamic changes to your requests and responses

Setup Dynamic API Authentication

Authentication tokens such as OAuth or an API key may be required In order to test your API. Find out how to configure the scan for dynamic authentication.

API Happy Path "Scanarios"

You can add additional operations and requests to your scan configuration scenario to create more complex test scenarios. Take a look at the video explainer.

Setup and Teardown using Global Blocks

Set up and tear down test resources or create test states to test the API using before and after blocks e.g. Create a new test user account, run tests and then delete the new user

Test for Broken Authorization

Find out how to test your APIs for Authorization vulnerabilities such as OWASP API 01:2023 - Broken Object Level Authorization (BOLA) or OWASP API 05:2023 - Broken Functional Level Authorization (BFLA) using the 42Crunch API Scan tool.

Latest Resources

WEBINAR

Mitigate OWASP API risks through security-by-design

Learn best practices and mitigation steps for some of the OWASP API vulnerabilities through this 42Crunch API security best practice webinar
Nov 5, 2024
PST 9am | EST 12pm | GMT 5pm

BLOG

Securing APIs in the Age of GenAI: Test Before You Connect

By Tom Chang | October 2, 2024

How to secure your APIs from GenAI and LLM based attacks Generative AI (GenAI) and Large Language Models (LLMs) are transforming the enterprise landscape, enhancing customer and employee experiences with unprecedented efficiency and insight. The recent McKinsey Global survey on AI reports that 65 percent of respondents say […]

DataSheet

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Ready to Learn More?

Developer-first solution for delivering API security as code.