Choose your language
Api security course
More than 2 million students worldwide

Api security course

Master every layer of API security, from reconnaissance and exploitation to secure design and enterprise governance. This course covers the OWASP API Security Top 10, hands-on attack techniques, and real-world testing methodology. Whether you are a penetration tester, developer, or security architect, you will gain the skills to find vulnerabilities before attackers do.

Dedika for businesses

What you will learn:

You will build a complete API security skill set starting with threat modelling and attack surface mapping, then move through authentication flaws, injection vulnerabilities, and rate limit bypasses. You will use industry tools like Burp Suite, ffuf, and OWASP ZAP to conduct structured assessments and document findings professionally. The course also covers secure API design patterns, zero-trust architecture, cloud-native deployments, and emerging threats including AI and LLM API risks. By the end, you will be equipped to lead API security assessments, harden production systems, and build repeatable security programmes at scale.

How you study in practice Api security course

How you practise Api security course

For businesses looking to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 39 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

API Security Fundamentals and Threat Landscape

  • Lesson 1 • API Threat Actors and Attack Motivations

    Profiles external attackers, malicious insiders, and automated bots targeting APIs. Grounds threat modelling in realistic adversary goals and capabilities.

  • Lesson 2 • API Data Flow and Trust Boundaries

    Maps how data moves between clients, APIs, and backends, identifying where trust boundaries exist. Connects data flow analysis to threat modelling in later chapters.

  • Lesson 3 • API Architecture and Communication Models

    Covers REST, GraphQL, gRPC, and SOAP architectures and how each exposes distinct security surfaces. Establishes vocabulary used throughout the course.

  • Lesson 4 • Common API Vulnerability Categories

    Introduces the OWASP API Security Top 10 as a structured taxonomy of API weaknesses. Provides context for the attack techniques covered in subsequent chapters.

  • Lesson 5 • Setting Up a Security Testing Lab

    Guides students through building a local API testing environment with vulnerable targets. Ensures hands-on readiness for all practical exercises in the course.

Chapter 2See details

API Reconnaissance and Attack Surface Mapping

  • Lesson 1 • Attack Surface Documentation

    Structures discovered endpoints, parameters, and authentication mechanisms into a prioritised attack surface report. Prepares students for systematic exploitation planning.

  • Lesson 2 • API Documentation Analysis

    Extracts security-relevant details from OpenAPI, Swagger, and Postman collections to identify risky endpoints. Teaches how documentation itself becomes an attacker resource.

  • Lesson 3 • Traffic Interception and Analysis

    Captures and decodes API traffic using proxy tools to reveal hidden parameters and authentication tokens. Directly feeds into the exploitation techniques in subsequent chapters.

  • Lesson 4 • Passive API Discovery Techniques

    Uses OSINT, public documentation, and traffic analysis to identify API endpoints without direct interaction. Establishes reconnaissance discipline before active scanning.

  • Lesson 5 • Active Endpoint Enumeration

    Applies fuzzing, wordlist-based scanning, and forced browsing to discover undocumented API routes. Builds on passive findings to expand the attack surface map.

Chapter 3See details

Authentication and Authorisation Mechanisms

  • Lesson 1 • OAuth 2.0 Flows and Security Pitfalls

    Breaks down authorisation code, implicit, and client credentials flows, highlighting where each introduces vulnerabilities. Prepares students to test OAuth implementations.

  • Lesson 2 • API Key Management and Weaknesses

    Examines how API keys are issued, transmitted, and stored, and where they fail. Connects poor key hygiene to real-world credential exposure incidents.

  • Lesson 3 • JSON Web Token Security

    Analyses JWT structure, signing algorithms, and common implementation errors that allow token forgery. Directly supports the authorisation bypass attacks covered next.

  • Lesson 4 • Function-Level Authorisation Failures

    Covers broken function-level authorisation where HTTP methods or admin endpoints are improperly restricted. Connects to API design review techniques in later chapters.

  • Lesson 5 • Broken Object-Level Authorisation

    Teaches identification and exploitation of BOLA/IDOR flaws where users access unauthorised resources. Builds skills for manual and automated authorisation testing.

Chapter 4See details

Input Validation and Injection Attacks

  • Lesson 1 • NoSQL and GraphQL Injection

    Explores operator injection in MongoDB-style APIs and introspection abuse in GraphQL endpoints. Extends injection concepts to non-relational and query-language APIs.

  • Lesson 2 • XML and Deserialisation Attacks

    Examines XXE injection in XML-accepting APIs and insecure deserialisation in object-based endpoints. Connects these attack classes to data exfiltration and remote code execution.

  • Lesson 3 • SQL Injection via API Endpoints

    Demonstrates how API parameters pass unsanitised input to SQL queries, enabling data extraction and manipulation. Covers both manual and tool-assisted detection methods.

  • Lesson 4 • Command and Server-Side Injection

    Covers OS command injection and server-side template injection triggered through API parameters. Highlights the critical severity of these vulnerabilities in API contexts.

  • Lesson 5 • Input Validation Principles for APIs

    Establishes allowlist validation, schema enforcement, and type checking as the foundation of injection defence. Sets the baseline for evaluating all injection attack surfaces.

Chapter 5See details

Rate Limiting, DoS, and Resource Abuse

  • Lesson 1 • API Denial-of-Service Techniques

    Covers application-layer DoS via large payloads, recursive queries, and regex complexity attacks. Connects resource exhaustion to availability risk in production APIs.

  • Lesson 2 • Rate Limiting Concepts and Bypass

    Explains token bucket, leaky bucket, and fixed-window rate limiting models and their bypass techniques. Establishes the foundation for testing API throttling controls.

  • Lesson 3 • Implementing Effective Throttling Controls

    Teaches configuration of rate limits, quotas, and circuit breakers at the API gateway and application layer. Provides remediation skills to complement the attack techniques above.

  • Lesson 4 • Business Logic Abuse via APIs

    Identifies how attackers exploit API workflows to gain financial or operational advantage beyond technical flaws. Bridges technical testing with business impact analysis.

Chapter 6See details

API Security Testing Methodology

  • Lesson 1 • Assessment Reporting and Evidence Collection

    Teaches structured vulnerability reporting with CVSS scoring, reproduction steps, and remediation guidance. Produces professional deliverables that communicate risk to technical and business audiences.

  • Lesson 2 • Vulnerability Chaining and Exploit Development

    Demonstrates how individual low-severity findings combine into high-impact exploit chains. Elevates students from finding individual bugs to demonstrating real business risk.

  • Lesson 3 • Assessment Scoping and Rules of Engagement

    Defines how to scope API assessments, establish testing boundaries, and document rules of engagement. Ensures legal and ethical clarity before any active testing begins.

  • Lesson 4 • Automated API Scanning Tools

    Covers configuration and use of automated scanners including DAST tools and API-specific fuzzers. Positions automation as a complement to, not replacement for, manual testing.

  • Lesson 5 • Manual Testing Techniques and Checklists

    Provides structured manual testing checklists covering authentication, authorisation, injection, and logic flaws. Ensures comprehensive coverage beyond automated tool capabilities.

Chapter 7See details

Secure API Design and Development Practices

  • Lesson 1 • Input Validation and Output Encoding

    Defines server-side validation, schema enforcement, and output encoding requirements that eliminate injection risks. Reinforces the attack techniques from Chapter 3 with developer-side controls.

  • Lesson 2 • Secure Authentication Implementation

    Specifies implementation requirements for OAuth 2.0, JWT, and API key systems that resist the attacks covered earlier. Connects attacker techniques to concrete developer countermeasures.

  • Lesson 3 • Authorisation Design Patterns

    Covers attribute-based, role-based, and object-level authorisation models that prevent BOLA and privilege escalation. Provides reusable design patterns applicable across API frameworks.

  • Lesson 4 • API Security Headers and Transport Security

    Specifies required HTTP security headers, TLS configuration, and certificate management for API endpoints. Provides a hardening checklist applicable to any API deployment.

  • Lesson 5 • Secure Error Handling and Logging

    Establishes standards for error responses that avoid information leakage whilst enabling effective debugging. Connects to the reconnaissance techniques attackers use to exploit verbose errors.

Chapter 8See details

API Security Architecture and Programme Management

  • Lesson 1 • API Inventory and Lifecycle Governance

    Establishes processes for maintaining a complete API inventory, managing versioning, and retiring deprecated endpoints. Addresses shadow API risk and governance gaps in large organisations.

  • Lesson 2 • Zero Trust Principles for APIs

    Applies zero trust concepts including mutual TLS, continuous verification, and least-privilege access to API ecosystems. Extends the authorisation design patterns from Chapter 7 to architectural scale.

  • Lesson 3 • API Gateway Security Architecture

    Designs gateway-layer controls including authentication enforcement, traffic inspection, and policy management. Positions the gateway as the primary enforcement point in API security architecture.

  • Lesson 4 • Threat Modelling for API Systems

    Applies STRIDE and data flow diagram techniques to API architectures to identify design-level threats. Integrates threat modelling into the API design review process.

  • Lesson 5 • Building a Continuous API Security Programme

    Defines the components of a mature API security programme including testing cadence, developer training, and metrics. Equips students to lead organisational API security improvement efforts.

Certification

Your valid completion certificate

This course is for you:

  • Penetration testers: ready to specialise their skills in API-focused engagements.

  • Backend developers: wanting to understand how their APIs get attacked and exploited.

  • Security engineers: responsible for reviewing and hardening APIs across their organisation.

  • DevSecOps practitioners: integrating security testing directly into API development pipelines.

  • IT professionals: transitioning into application security roles with API-heavy environments.

  • Bug bounty hunters: looking to expand their scope into API vulnerability discovery.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast and simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top qualifications

FAQ

Who is Dedika?

Is the certificate valid in the United Kingdom?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course