API Security Workshop

Powered by Akamai API Security | Hands-on OWASP API Top 10 + AI API Security

Your Credentials

Email: participantXX@workshop.lab  (XX = your number, 01–20)
Password: Workshop@2026

Workshop Resources

🎓 Setup — start here

Pick your participant number, import the Hoppscotch collection + environment in two clicks, then follow the attack walkthrough.

Open Setup →

📋 Pre-Requisites

What you need before the workshop starts. Check your environment access.

View Pre-Requisites →

📖 Workshop Guide

Full step-by-step follow-along guide: API Discovery, BOLA Attack, AI API Security, Findings Review.

Open Workshop Guide →

⚡ Quick Reference

One-page cheat sheet: all URLs, endpoints, and environment variables for Hoppscotch.

Quick Reference →

🔒 Facilitator Guide

German facilitator notes: server access, UUID table, troubleshooting, reset procedure between sessions.

Facilitator Guide →

📦 Import Hoppscotch Collection

Pre-built API requests for all workshop modules. Import this into Hoppscotch.

Download collection.json →

Lab Environment URLs

ServiceURLPurpose
crAPIcrapi.security-lab.cloudMain vulnerable API target
MailHogmailhog.security-lab.cloudFake email inbox
Hoppscotchhoppscotch.security-lab.cloudAPI client — use this for all requests
AI APIai.security-lab.cloudVulnerable AI/LLM API (OpenAI-compatible)
APISec Consoleapisec.security-lab.cloudAkamai API Security — findings dashboard

Workshop Modules

#ModuleOWASPDuration
1API Discovery20 min
2BOLA AttackAPI1:202350 min
3AI API SecurityAPI3, API5, API8, API1045 min
4Findings Review30 min