VAmPI

VAmPI

Vulnerable REST API for security testing

Description

Practicing API security testing on real sites isn't an option, and most training targets are web apps. VAmPI is a deliberately vulnerable REST API with the OWASP API Top 10 for practicing and evaluating API security testing.

Toggle vulnerabilities on and off to test scanners or run training, deployed with Docker.

Features



OWASP:API Top 10.

Toggle:Compare runs.

Scanner evaluation:Test tools.

Docker:Quick setup.