Powered by Akamai API Security | Hands-on OWASP API Top 10 + AI API Security
Pick your participant number, import the Hoppscotch collection + environment in two clicks, then follow the attack walkthrough.
Open Setup →What you need before the workshop starts. Check your environment access.
View Pre-Requisites →Full step-by-step follow-along guide: API Discovery, BOLA Attack, AI API Security, Findings Review.
Open Workshop Guide →One-page cheat sheet: all URLs, endpoints, and environment variables for Hoppscotch.
Quick Reference →German facilitator notes: server access, UUID table, troubleshooting, reset procedure between sessions.
Facilitator Guide →Pre-built API requests for all workshop modules. Import this into Hoppscotch.
Download collection.json →| Service | URL | Purpose |
|---|---|---|
| crAPI | crapi.security-lab.cloud | Main vulnerable API target |
| MailHog | mailhog.security-lab.cloud | Fake email inbox |
| Hoppscotch | hoppscotch.security-lab.cloud | API client — use this for all requests |
| AI API | ai.security-lab.cloud | Vulnerable AI/LLM API (OpenAI-compatible) |
| APISec Console | apisec.security-lab.cloud | Akamai API Security — findings dashboard |
| # | Module | OWASP | Duration |
|---|---|---|---|
| 1 | API Discovery | — | 20 min |
| 2 | BOLA Attack | API1:2023 | 50 min |
| 3 | AI API Security | API3, API5, API8, API10 | 45 min |
| 4 | Findings Review | — | 30 min |