Skip to main content
Be Bitwise

API Security

API architectures, the OWASP API Security Top 10, authentication attacks, BOLA/IDOR, GraphQL hacking, and advanced API exploitation.

Recommended Prerequisites

These are recommendations - you can start this track at any time.

About this track

API architectures, the OWASP API Security Top 10, authentication attacks, BOLA/IDOR, GraphQL hacking, and advanced API exploitation.

The API Security track collects 3 modules and 12 lessons into a single ordered path. Each module ends with a checkpoint quiz; passing the checkpoint unlocks the next module so you can track your progress without guessing whether the material has stuck.

You start with "API Security Fundamentals" and finish on "Advanced API Exploitation". The whole track sits inside the Applied Security area of the curriculum, so the writing assumes the prerequisites listed above and skips ground that an earlier track has already covered.

What this track covers

  • API Security FundamentalsUnderstand how modern APIs are built and where they break. Survey REST, GraphQL, gRPC, and WebSocket architectures, learn how authentication and authorisation work in APIs, and study the OWASP API Security Top 10.
  • API Vulnerability ClassesHands-on exploration of the most common API vulnerabilities. Exploit Broken Object Level Authorisation, injection and mass assignment flaws, resource exhaustion, and business logic bugs in realistic API scenarios.
  • Advanced API ExploitationGo beyond REST. Attack GraphQL APIs through introspection and nested query abuse, exploit gRPC reflection and protobuf deserialization, hijack WebSocket connections, and learn to chain API vulnerabilities into high-impact attack scenarios.

How the track works

Every lesson is a short page with diagrams, runnable examples, and the kind of edge-case footnotes you usually only find in textbooks. Where it makes sense, the lesson is paired with a CPU simulation or a coding challenge so you can poke at the idea instead of just reading about it.

The lessons themselves are free to read with a free account. The 3 checkpoint quizzes that gate the next module are also free, as are the lesson IDE and CPU simulations. Optional 777-tier tools — the step-through debugger, decompiler, ROP gadget builder, heap visualiser, and exploit labs — sit alongside the lessons but are not required to follow the track from start to finish.

You can jump in at any point. Be Bitwise is built around a free forever curriculum, with no time limits and no expiring access. Pick the next lesson when you have an hour; come back when you do not.