Before testing APIs, you need the right toolset. The core tools are: Burp Suite (intercepting proxy), Postman or Insomnia (API client), and a vulnerable target like DVWS or crAPI.
💡 crAPI (Completely Ridiculous API) is an intentionally vulnerable API application built by OWASP for practicing all API Top 10 vulnerabilities.
Verify exercises to earn ★ 80 XP and unlock next lab level.