Tutorials

API Security & Conformance Scan using OpenAPI Swagger Editor Extension in VS Code

A dynamic security scan of your API to check for conformance against the API design (OpenAPI contract) and security vulnerabilities such as BOLA and BFLA. The tutorial videos below are for OpenAPI Editor in Microsoft Visual Studio Code (VS Code). API Scan is also available on the 42Crunch Platform and in GitHub Actions CI/CD.

Activate API Scan CLI

You can run the dynamic API Scan security test locally on your machine without having to share the API. The video explains how. if you are a paying customer you can run the scan in your IDE on local APIs or on APIs in your customer account on the 42Crunch platform

Overview of the Scan Configuration

Explanation of the Scan configuration view where you configure and run your scan tests

Running your first API Scan

Learn how to configure and run your first API Scan and read the results

API Request Chaining

You can add additional operations and requests to your scan configuration scenario to create more complex test scenarios. Take a look at the video explainer.

Create Test Resources using Global Blocks

Set up and tear down test resources or create test states to test the API using before and after blocks e.g. Create a new test user account, run tests and then delete the new user

API Testing with Dynamic Authentication

Authentication tokens such as OAuth or an API key may be required In order to test your API. Find out how to configure the scan for dynamic authentication.

Test for Broken Authorization

Find out how to test your APIs for Authorization vulnerabilities such as OWASP API 01:2023 - Broken Object Level Authorization (BOLA) or OWASP API 05:2023 - Broken Functional Level Authorization (BFLA) using the 42Crunch API Scan tool.

Latest Resources

WEBINAR

Top Things You Need to Know About API Security

Two of the API security industry’s leading experts, Dr Philippe de Ryck and Isabelle Mauny, guide you through some real-world cases of API security attacks and also share some best practices for securing your APIs.

BLOG

Addressing API Security Regulations in Financial Services

By Colin Domoney | April 10, 2024

Introduction APIs are disrupting almost every industry vertical, and nowhere is their impact more profound than in the financial services industry. Whether helping modernize legacy systems or creating entirely new business opportunities through innovations such as OpenBanking, APIs are the lifeblood of the financial services industry. At the […]

DataSheet

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Ready to Learn More?

Developer-first solution for delivering API security as code.