Everything related to attacking and securing modern APIs including REST, GraphQL, gRPC, and more. Covers broken authentication, IDOR, mass assignment, BOLA, rate limiting, and JWT flaws. Includes real-world exploits, recon techniques, gateway bypasses, and best-in-class tooling for testing and exploitation.

JWT Debugger is a web application to create, encode, decode, and debug JWT (JSON Web Tokens).

Moxy is an open-source DAST tool with agentic AI for modern web application security testing and automated pentesting workflows.

AI-driven pentesting platform automating hacker intuition to find vulnerabilities before exploits, reducing discovery costs.

AI-infused API Security solution for the entire API lifecycle, from discovery and posture management to threat protection, including AI Agents.