Application & API Security

OWASP API Top 10

OWASP API Security Top 10

Community Global OWASP Since 2019

The API-specific risk list: broken object level authorisation, broken authentication, broken object property level authorisation, unrestricted resource consumption, and the rest of the failures that dominate real API breaches.

Authorisation failures top the list because APIs expose object identifiers directly, the same shape of mistake that turns a data product output port into an unintended bulk export.

At a glance

Category
Application & API Security
Jurisdiction
Global
Governance
OWASP
Status
2023 edition
First released
2019

Links

Related frameworks

Other entries under Application & API Security.

See OWASP API Top 10 in context

Open the interactive Data Landscape for Regulation to compare OWASP API Top 10 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.