{"id":859,"date":"2022-04-27T19:43:36","date_gmt":"2022-04-27T18:43:36","guid":{"rendered":"https:\/\/42crdev.prexihost.com\/?page_id=859"},"modified":"2024-02-13T10:25:43","modified_gmt":"2024-02-13T10:25:43","slug":"api-security-testing","status":"publish","type":"page","link":"https:\/\/staging2022.42crunch.com\/api-security-testing\/","title":{"rendered":"API Security Testing"},"content":{"rendered":"\n\n\t\t

\n\t\t\tAPI Security Testing\n\t\t<\/h1>\n\t\t\t

Identify API security flaws, risks and vulnerabilities<\/p>\t\t\n\t\t\t\n\t\t\t\t\t\t\tAPI Security Testing Datasheet\n\t\t\t\t\t<\/a>\n\t\t\t\t\"DevSecOps-API\n\t

API Security Testing is enforced by the 42Crunch API Security Audit<\/a> and API Conformance & Security Scan<\/a> tools.\u00a0\u00a0For further runtime protection, API Protect can be added.<\/p>\n

\n\t\tAPI Security Testing During API Design & Development\n\t<\/h2>\n\t

Because APIs are specified earliest in the SDLC and have a defined OpenAPI contract (via OpenAPI \/ Swagger) they are ideally suited to a preemptive “shift left” API security testing approach. 42Crunch’s API Audit<\/a> enables the testing of the OpenAPI contract and API Scan<\/a> enables the testing of the underlying implementation of the API. Both are available in developer IDEs<\/a> and CI\/CD Platforms<\/a>. Try some of our\u00a0free API testing tools<\/a>\u00a0for developer and security teams.<\/p>\n\t\t\t\t\"Figure\n\t\t\t\t\n\t\t\t\t\"API\n\t\t\t\t<\/a>\n

\n\t\tInstant Scoring of the OpenAPI Contract\n\t<\/h2>\n\t

The 42Crunch API Security Audit<\/a> automatically performs a static analysis of your OpenAPI (Swagger) definition file to ensure the definition adheres to the specification and to catch any security issues as per the OWASP API Security Top 10<\/a>.<\/p>\n

\n\t\tAudit Your OpenAPI Contract for OWASP API Top 10 Vulnerabilities\n\t<\/h2>\n\t

An API Audit report is auto-generated capturing API vulnerabilities in the OpenAPI contract such as mass assignment, data\/exception leakage, weak authentication schemes, injection vulnerabilities and lack of resource control.<\/p>\n\t\t\t\t\n\t\t\t\t\"Audit\n\t\t\t\t<\/a>\n

\n\t\tFree Online Audit of Your OpenAPI Contract\n\t<\/h2>\n\t