🛡️

Akamai API Security Lab

Complete Lab Portal — all services & dashboards

← APISec Console

Lab Portal

All URLs for the Akamai API Security demo environment · 172.236.213.192

Platform
Live Dashboards
OWASP API Top 10 — Primary Target
Workshop
🎓
Setup — start here
portal.security-lab.cloud/workshop/setup
Pick your participant number, import the Hoppscotch collection + environment in two clicks, then follow the attack walkthrough.
1 · Pre-Requisites
portal.security-lab.cloud/workshop/prework
What to check before the workshop starts — browser, access, credentials.
📖
2 · Workshop Guide
portal.security-lab.cloud/workshop/guide
Full step-by-step follow-along: discovery, BOLA, AI API security, findings review.
Quick Reference
portal.security-lab.cloud/workshop/quick-reference
One-page cheat sheet: URLs, endpoints, environment variables.
🧭
Facilitator Guide DE
portal.security-lab.cloud/workshop/facilitator
German facilitator notes: server access, reset runbook, troubleshooting.
🚗
crAPI — Attack Target
crapi.security-lab.cloud
The main application under attack. Participants reach it through Hoppscotch — no direct login needed, accounts are pre-created (participantNN@workshop.lab).
🟢
Hoppscotch — API Client
hoppscotch.security-lab.cloud
The API client used for every request against crAPI. The bottom-right “🎓 Workshop Setup” button jumps back to the setup page.
📬
MailHog optional
mailhog.security-lab.cloud
Only needed if someone registers a new account (OTP/confirmation lands here). Not required for the workshop — participant accounts already exist.
🎬
Live Attack Demo 🔒 password
portal.security-lab.cloud/workshop/demo
Presenter-driven 3-panel attack walkthrough. Protected by the demo password.
⚠️
Reset Workshop 🔒 facilitators only
portal.security-lab.cloud/workshop/reset
Cleans participant data before a new event. Separate password — participants cannot run this. Dry-run preview, then apply.
REST & GraphQL APIs
Web Application Targets