Skip to main content

API Security Testing Playbook (OWASP API Top 10)

Build an OWASP API Top 10 testing playbook: BOLA, auth, mass assignment, rate-limit, and SSRF test cases with ready-to-run curl commands.

Fill in the placeholders

Edit the values, then copy your finished prompt.

Your Prompt
prompt.txt
Create a detailed API security testing playbook for a multi-tenant SaaS REST API handling user data and billing.

**API details:**
- Architecture: REST with OpenAPI 3.1 spec, some GraphQL for reporting
- Authentication: OAuth 2.0 + JWT bearer tokens with refresh rotation
- Authorization model: RBAC with organization-scoped permissions
- Number of endpoints: approximately 85
- Data sensitivity level: PII + payment card data (PCI DSS scope)

**Generate test cases for each OWASP API Security Top 10 (2023) category:**

1. **API1:2023 — Broken Object Level Authorization (BOLA):**
   - Test horizontal privilege escalation by swapping object IDs in URLs/params
   - Test IDOR across all CRUD operations (GET, PUT, DELETE)
   - Test UUID guessability and sequential ID enumeration
   - Provide curl/httpie commands for each test case

2. **API2:2023 — Broken Authentication:**
   - Test credential stuffing resistance (rate limiting on login)
   - Test JWT vulnerabilities: algorithm confusion (none/HS256 to RS256), expired token acceptance, token replay
   - Test session fixation and token rotation on privilege changes
   - Test password reset flow for account takeover vectors

3. **API3:2023 — Broken Object Property Level Authorization:**
   - Test mass assignment by sending extra fields in POST/PUT requests
   - Test response filtering — does the API return sensitive fields (password hash, SSN, internal IDs)?
   - Test field-level access control (can a regular user modify admin-only fields?)

4. **API4:2023 — Unrestricted Resource Consumption:**
   - Test rate limiting: per-user, per-IP, per-endpoint, and global limits
   - Test pagination abuse (requesting page_size=999999)
   - Test GraphQL complexity/depth limits (if applicable)
   - Test file upload size limits and zip bomb protection
   - Test regex DoS (ReDoS) on search/filter parameters

5. **API5:2023 — Broken Function Level Authorization:**
   - Test admin endpoints accessible to regular users
   - Test HTTP method tampering (GET to PUT/DELETE on read-only endpoints)
   - Test hidden/undocumented endpoints via wordlist fuzzing

6. **API6-10 coverage:**
   - Unrestricted access to sensitive business flows (coupon abuse, signup spam)
   - Server-Side Request Forgery (SSRF) via URL parameters
   - Security misconfiguration (CORS, verbose errors, debug mode, default credentials)
   - Improper inventory management (old API versions still accessible)
   - Unsafe consumption of external APIs (webhook validation, SSRF via integrations)

7. **Testing toolkit setup:**
   - Burp Suite configuration with relevant extensions
   - Postman/Newman collection structure for automated regression
   - Python with requests + pytest script for CI/CD integration
   - Custom wordlists for endpoint discovery

8. **Reporting template:**
   - Finding severity classification (CVSS 4.0 scoring)
   - Reproduction steps with request/response pairs
   - Remediation recommendations with code examples
   - Risk acceptance criteria for findings that cannot be immediately fixed

Prioritize test cases by likelihood of exploitation and business impact.

What this prompt does

This prompt builds a hands-on API security testing playbook organized around the OWASP API Security Top 10 (2023). You describe the [api_description], [api_architecture], [auth_mechanism], [authz_model], [endpoint_count], and [data_sensitivity], and it generates concrete test cases — with runnable curl/httpie commands — for each category, plus a testing toolkit setup and a reporting template.

The structure works because it follows the real exploitation order: it starts with Broken Object Level Authorization (BOLA) and Broken Authentication, which is where most real API breaches actually happen, then works through mass assignment, resource consumption, function-level authorization, SSRF, and misconfiguration. By keying tests to your [authz_model] and [auth_mechanism], the JWT, IDOR, and privilege-escalation cases target your actual setup. The [automation_tool] slot turns the playbook into a regression suite you can wire into CI.

When to use it

  • You've built an API and want to test it against the OWASP API Top 10 before or after launch.
  • You need runnable curl/httpie cases, not an abstract checklist, to actually probe BOLA and auth flaws.
  • You're handling sensitive data ([data_sensitivity] like PII or PCI scope) and need documented security testing.
  • You want a Postman/Newman or [automation_tool] regression suite wired into CI to guard every deploy.
  • You're reviewing a multi-tenant API where object-level authorization is the highest risk.
  • You need a CVSS-scored reporting template with reproduction steps for findings.

Example output

You get a category-by-category playbook: BOLA tests that swap object IDs across CRUD operations, broken-auth tests probing JWT algorithm confusion and token replay, mass-assignment and response-filtering checks, resource-consumption tests (rate limits, pagination abuse, ReDoS), function-level authorization tests, and SSRF/misconfiguration coverage — each with curl or httpie commands. It closes with a toolkit setup (Burp, Postman/Newman, your [automation_tool]) and a CVSS 4.0 reporting template with reproduction steps and remediation.

Pro tips

  • Describe [authz_model] precisely (RBAC, org-scoped, tenant isolation); the BOLA and privilege-escalation tests are built around it.
  • Specify your exact [auth_mechanism] so the JWT and session tests match your token and refresh setup.
  • Set [data_sensitivity] honestly — PCI or PII scope raises the priority of response-filtering and mass-assignment tests.
  • Use [automation_tool] to get a regression script you can run in CI, not just one-off manual commands.
  • Only run these tests against systems you own or are authorized to test; the playbook is for defensive work.
  • Start with BOLA and broken auth as the prompt orders them — that's where the highest-impact findings usually are.

Frequently Asked Questions

Which OWASP standard does this cover?
The OWASP API Security Top 10, 2023 edition — including BOLA (API1), Broken Authentication (API2), Broken Object Property Level Authorization (API3), and the rest through improper inventory management and unsafe consumption of external APIs. Each category gets concrete, runnable test cases.
Does it give me commands I can actually run?
Yes. It generates curl and httpie commands for each test case, such as swapping object IDs to probe BOLA or sending extra fields to test mass assignment. Only run them against APIs you own or have explicit authorization to test.
Can I automate these tests in my CI pipeline?
It produces a Postman/Newman collection structure and a script in your chosen `[automation_tool]` (for example Python with requests and pytest) so you can wire the regression suite into CI/CD and re-run the same checks on every deploy.
Will it work for GraphQL APIs too?
Partially. If you note GraphQL in `[api_architecture]`, it includes complexity and depth-limit tests under unrestricted resource consumption. The bulk of the playbook is REST-oriented, so GraphQL-specific concerns like introspection abuse may need additional manual coverage.
Engr Mejba Ahmed

Need this built for real?

Engr Mejba Ahmed

AI Developer · Software Engineer

I'm Mejba — I design and ship production AI systems, automations, and full-stack apps. If you want this turned into a working solution for your team, let's talk.

More in Cybersecurity Prompts

Engr Mejba Ahmed

Engr Mejba Ahmed

AI assistant · trained on my work

👋

Hey there!

Quick Actions

WhatsApp Direct line to me

Chat on WhatsApp

+880 1723 741224 · Replies within the hour on working days

Popular Questions

Engr Mejba Ahmed is connected
Engr Mejba Ahmed is typing...
Engr Mejba Ahmed avatar

✉ Want me to follow up? Drop your email

Engr Mejba Ahmed avatar

📞 Connect Directly

Choose how you'd like to reach me

WhatsApp

+880 1723 741224

Email

mejba.13@gmail.com

✓ Details sent! I'll get back to you shortly.

Powered by OpenAI

335+

Blog Posts

25

AI Courses

63

Projects

Services & Expertise

Pricing & Process

Learning & Resources

Connect & Support