{"id":133942,"url":"https://github.com/brandonhimpfen/awesome-api-security","name":"awesome-api-security","description":"A curated list of tools, frameworks, standards, platforms, research, and learning resources for securing APIs.","projects_count":72,"last_synced_at":"2026-08-06T13:00:23.380Z","repository":{"id":363350329,"uuid":"1262956837","full_name":"brandonhimpfen/awesome-api-security","owner":"brandonhimpfen","description":"A curated list of tools, frameworks, standards, platforms, research, and learning resources for securing APIs.","archived":false,"fork":false,"pushed_at":"2026-06-08T13:36:57.000Z","size":18,"stargazers_count":3,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-18T06:05:25.995Z","etag":null,"topics":["api","api-security","awesome","awesome-list","awesome-lists"],"latest_commit_sha":null,"homepage":"https://lnktr.net/awesome","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/brandonhimpfen.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":null,"code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":"CITATION.cff","codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"github":"brandonhimpfen","ko_fi":"brandonhimpfen","buy_me_a_coffee":"brandonhimpfen","custom":["https://paypal.me/brandonhimpfen","https://www.brandonhimpfen.com/#/portal/support"]}},"created_at":"2026-06-08T13:35:31.000Z","updated_at":"2026-06-08T20:41:07.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/brandonhimpfen/awesome-api-security","commit_stats":null,"previous_names":["brandonhimpfen/awesome-api-security"],"tags_count":0,"template":false,"template_full_name":"brandonhimpfen/awesome-lists-template","purl":"pkg:github/brandonhimpfen/awesome-api-security","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/brandonhimpfen%2Fawesome-api-security","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/brandonhimpfen%2Fawesome-api-security/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/brandonhimpfen%2Fawesome-api-security/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/brandonhimpfen%2Fawesome-api-security/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/brandonhimpfen","download_url":"https://codeload.github.com/brandonhimpfen/awesome-api-security/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/brandonhimpfen%2Fawesome-api-security/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36336280,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"ssl_error","status_checked_at":"2026-08-06T04:43:02.660Z","response_time":54,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2026-06-12T13:31:53.775Z","updated_at":"2026-08-06T13:00:23.380Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Communities","API Security Testing","API Gateways \u0026 Protection","Authentication \u0026 Authorization","API Security Monitoring","API Discovery \u0026 Inventory","License","API Specifications \u0026 Standards","Learning Resources","API Security Platforms","Related Awesome Lists"],"sub_categories":[],"readme":"# Awesome API Security [![Awesome Lists](https://srv-cdn.himpfen.io/badges/awesome-lists/awesomelists-flat.svg)](https://github.com/brandonhimpfen/awesome-lists)\n\n[![Support Open Work](https://img.shields.io/badge/Support-Open%20Work-0A0A0A?style=flat\u0026logo=github)](https://github.com/brandonhimpfen/support)\n[![X](https://srv-cdn.himpfen.io/badges/twitter/twitter-flat.svg)](https://x.com/ListsAwesome)\n[![Facebook](https://srv-cdn.himpfen.io/badges/facebook-pages/facebook-pages-flat.svg)](https://www.facebook.com/awesomelists)\n\n\u003e A curated list of tools, frameworks, standards, platforms, research, and learning resources for securing APIs.\n\nAPIs power modern applications, cloud services, mobile platforms, and distributed systems. As APIs increasingly become the primary attack surface for organizations, securing them is essential for protecting data, services, users, and infrastructure.\n\nThis list is intended for developers, security engineers, AppSec teams, DevSecOps practitioners, architects, platform teams, auditors, and researchers working with API security.\n\n_Support ongoing maintenance and curation via [GitHub Sponsors](https://github.com/sponsors/brandonhimpfen)._\n\n## Contents\n\n- [API Security Testing](#api-security-testing)\n- [API Security Platforms](#api-security-platforms)\n- [API Gateways \u0026 Protection](#api-gateways--protection)\n- [Authentication \u0026 Authorization](#authentication--authorization)\n- [API Discovery \u0026 Inventory](#api-discovery--inventory)\n- [API Security Monitoring](#api-security-monitoring)\n- [API Specifications \u0026 Standards](#api-specifications--standards)\n- [Learning Resources](#learning-resources)\n- [Communities](#communities)\n- [Related Awesome Lists](#related-awesome-lists)\n\n## API Security Testing\n\nTools and platforms for discovering vulnerabilities, misconfigurations, and security weaknesses in APIs.\n\n- [OWASP ZAP](https://www.zaproxy.org/) — Open-source web application and API security testing platform.\n- [Burp Suite](https://portswigger.net/burp) — Security testing platform with API assessment capabilities.\n- [Postman](https://www.postman.com/) — API platform supporting automated security and functional testing.\n- [Insomnia](https://insomnia.rest/) — API testing platform supporting REST, GraphQL, and gRPC.\n- [Schemathesis](https://schemathesis.io/) — Property-based API testing using OpenAPI schemas.\n- [42Crunch API Security Testing](https://42crunch.com/) — API-focused security testing and compliance platform.\n- [Tinfoil](https://github.com/tinfoilsh/tinfoil) — Open-source API security scanning and analysis tool.\n- [Dredd](https://dredd.org/) — API contract testing against documentation and specifications.\n\n## API Security Platforms\n\nComprehensive platforms designed to secure APIs across development and production environments.\n\n- [42Crunch](https://42crunch.com/) — API security platform covering design, testing, and runtime protection.\n- [Salt Security](https://salt.security/) — API protection and threat detection platform.\n- [Noname Security](https://nonamesecurity.com/) — API security posture management and protection.\n- [Traceable AI](https://www.traceable.ai/) — API security and observability platform.\n- [Akamai API Security](https://www.akamai.com/) — API discovery, monitoring, and protection capabilities.\n- [Imperva API Security](https://www.imperva.com/) — API attack detection and protection platform.\n- [Wallarm](https://wallarm.com/) — API and application security platform.\n- [Data Theorem](https://www.datatheorem.com/) — API security posture management and vulnerability detection.\n\n## API Gateways \u0026 Protection\n\nGateways, proxies, and infrastructure components that help secure API traffic.\n\n- [Kong Gateway](https://konghq.com/) — API gateway with authentication, rate limiting, and security plugins.\n- [NGINX API Gateway](https://www.nginx.com/) — API management and traffic protection platform.\n- [Apache APISIX](https://apisix.apache.org/) — Cloud-native API gateway with security controls.\n- [Tyk](https://tyk.io/) — Open-source API gateway and management platform.\n- [Apigee](https://cloud.google.com/apigee) — API management platform from Google Cloud.\n- [AWS API Gateway](https://aws.amazon.com/api-gateway/) — Managed API gateway service.\n- [Azure API Management](https://azure.microsoft.com/en-us/products/api-management) — API governance and security platform.\n- [Envoy Proxy](https://www.envoyproxy.io/) — High-performance service proxy widely used in API architectures.\n\n## Authentication \u0026 Authorization\n\nStandards, frameworks, and identity systems for securing API access.\n\n- [OAuth 2.0](https://oauth.net/2/) — Industry-standard authorization framework.\n- [OpenID Connect](https://openid.net/connect/) — Identity layer built on OAuth 2.0.\n- [Keycloak](https://www.keycloak.org/) — Open-source identity and access management platform.\n- [Auth0](https://auth0.com/) — Identity platform supporting API authentication and authorization.\n- [ORY](https://www.ory.sh/) — Open-source identity and access management ecosystem.\n- [OpenFGA](https://openfga.dev/) — Authorization engine inspired by Google Zanzibar.\n- [Zitadel](https://zitadel.com/) — Identity and access management platform.\n- [Casbin](https://casbin.org/) — Authorization library supporting RBAC and ABAC models.\n\n## API Discovery \u0026 Inventory\n\nTools for identifying, cataloging, and managing API assets.\n\n- [Akto](https://github.com/akto-api-security/akto) — Open-source API discovery and security testing platform.\n- [Traceable API Inventory](https://www.traceable.ai/) — API discovery and asset inventory capabilities.\n- [Salt Security API Inventory](https://salt.security/) — API asset discovery and classification.\n- [Postman API Network](https://www.postman.com/explore) — API catalog and discovery platform.\n- [SwaggerHub](https://swagger.io/tools/swaggerhub/) — API design and governance platform.\n- [Backstage](https://backstage.io/) — Internal developer portal supporting API catalogs.\n\n## API Security Monitoring\n\nObservability and runtime monitoring tools for detecting attacks and anomalous API behavior.\n\n- [Wallarm](https://wallarm.com/) — Runtime API threat detection and monitoring.\n- [Traceable AI](https://www.traceable.ai/) — API behavior analysis and attack detection.\n- [Datadog API Monitoring](https://www.datadoghq.com/) — Monitoring and observability for APIs and services.\n- [New Relic](https://newrelic.com/) — Application and API observability platform.\n- [Elastic Observability](https://www.elastic.co/observability) — Monitoring, logging, and security analytics.\n- [Grafana](https://grafana.com/) — Visualization and monitoring platform for API telemetry.\n\n## API Specifications \u0026 Standards\n\nStandards and guidance that support secure API design and governance.\n\n- [OWASP API Security Top 10](https://owasp.org/www-project-api-security/) — Common API security risks and mitigations.\n- [OpenAPI Specification](https://www.openapis.org/) — Standard for describing REST APIs.\n- [AsyncAPI](https://www.asyncapi.com/) — Specification for event-driven APIs.\n- [JSON Web Token (JWT)](https://jwt.io/) — Open standard for transmitting claims securely.\n- [FAPI](https://openid.net/fapi/) — Financial-grade API security standards.\n- [OAuth Security Best Current Practice](https://datatracker.ietf.org/doc/html/draft-ietf-oauth-security-topics) — Security recommendations for OAuth implementations.\n\n## Learning Resources\n\nBooks, documentation, courses, and educational resources.\n\n- [OWASP API Security Project](https://owasp.org/www-project-api-security/) — Security guidance, references, and testing resources.\n- [API Security in Action](https://www.manning.com/books/api-security-in-action) — Practical guide to securing APIs.\n- [PortSwigger Web Security Academy](https://portswigger.net/web-security) — Free security training including API security topics.\n- [Google API Design Guide](https://cloud.google.com/apis/design) — API design principles and recommendations.\n- [Microsoft REST API Guidelines](https://github.com/microsoft/api-guidelines) — Guidance for API design and governance.\n- [OpenAPI Initiative](https://www.openapis.org/) — Documentation and resources for API standards.\n\n## Communities\n\nCommunities, organizations, and initiatives focused on API security.\n\n- [OWASP](https://owasp.org/) — Open community dedicated to application security.\n- [OpenAPI Initiative](https://www.openapis.org/) — Industry consortium supporting API standards.\n- [API Security Project](https://owasp.org/www-project-api-security/) — OWASP project focused on API security.\n- [Cloud Native Computing Foundation](https://www.cncf.io/) — Community supporting cloud-native infrastructure and API ecosystems.\n- [OpenSSF](https://openssf.org/) — Open source security community and initiatives.\n\n## Related Awesome Lists\n\n- [Awesome APIs](https://github.com/brandonhimpfen/awesome-apis) — A curated list of high-quality APIs, SDKs, and developer tools.\n- [Awesome Cybersecurity](https://github.com/brandonhimpfen/awesome-cybersecurity) — Cybersecurity frameworks and tools.\n- [Awesome AI Security](https://github.com/brandonhimpfen/awesome-ai-security) — Tools, frameworks, benchmarks, research, and resources focused on securing AI systems.\n- [Awesome Mobile Security](https://github.com/brandonhimpfen/awesome-mobile-security) — Tools, frameworks, and practices for securing mobile applications.\n- [Awesome Privacy](https://github.com/brandonhimpfen/awesome-privacy) — Tools and knowledge to protect digital privacy.\n- [Awesome Threat Intelligence](https://github.com/brandonhimpfen/awesome-threat-intelligence) — Threat detection and analysis resources.\n- [Awesome DevOps](https://github.com/brandonhimpfen/awesome-devops) — A curated list of tools, resources, and best practices in DevOps.\n- [Awesome Cloud](https://github.com/brandonhimpfen/awesome-cloud) — A curated list of cloud platforms, tools, SDKs, infrastructure services, and learning resources.\n- [Awesome Software Architecture](https://github.com/brandonhimpfen/awesome-software-architecture) — Architectural patterns, frameworks, tools, and resources for software systems.\n- [Awesome Web Development](https://github.com/brandonhimpfen/awesome-web-development) — Frameworks, tools, and learning resources for modern web development.\n\n## Contribute\n\nContributions are welcome. Please ensure your submission fully follows the requirements outlined in [`CONTRIBUTING.md`](CONTRIBUTING.md), including formatting, scope alignment, and category placement.\n\nPull requests that do not adhere to the contribution guidelines may be closed.\n\n## License\n\n[![CC0](https://mirrors.creativecommons.org/presskit/buttons/88x31/svg/by-sa.svg)](http://creativecommons.org/licenses/by-sa/4.0/)\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/brandonhimpfen%2Fawesome-api-security/projects"}