Securing Your API: The OWASP API Top 10

A presentation at PHP Sussex in September 2026 in Brighton, UK by Rob Allen

Slide 1

Slide 1

Securing Your API: The OWASP API Top 10 Rob Allen, September 2026

Slide 2

Slide 2

57% of organizations suffered an API-related data breach in the past two years Traceable 2025 Global State of API Security report Rob Allen ~ akrabat.com

Slide 3

Slide 3

Why are APIs different? Rob Allen ~ akrabat.com

Slide 4

Slide 4

The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs Rob Allen ~ akrabat.com

Slide 5

Slide 5

OWASP API Security Top 10 Rob Allen ~ akrabat.com

Slide 6

Slide 6

OWASP API Security Top 10 Rob Allen ~ akrabat.com

Slide 7

Slide 7

Who are you and what can you access? Authentication and authorisation failures Rob Allen ~ akrabat.com

Slide 8

Slide 8

Broken Authentication APIs that don’t properly verify who you are #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 9

Slide 9

Broken Authentication APIs that don’t properly verify who you are • Weak/no token validation • Missing expiration on tokens • Credential stuffing attacks #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 10

Slide 10

Broken Authentication Examples • API accepts JWT without verifying the signature • Login endpoint allows unlimited password attempts #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 11

Slide 11

Broken Authentication Prevention • Use established standards (OAuth 2.0, OpenID Connect) • Implement proper token validation and expiration • Rate limiting on auth endpoints #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 12

Slide 12

Broken Function Level Authorisation Users can access functionality they shouldn’t #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 13

Slide 13

Broken Function Level Authorisation Users can access functionality they shouldn’t • Incorrect authorisation check on a function or resource • Legitimate calls to endpoints that the user shouldn’t have access to • Undocumented open endpoints #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 14

Slide 14

Broken Function Level Authorisation Examples • /debug/dump • /admin/users doesn’t check that the caller is an admin #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 15

Slide 15

Broken Function Level Authorisation Prevention • Deny by default • Check roles/permissions on every endpoint • Don’t rely on hiding endpoints from documentation #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 16

Slide 16

Broken Object Level Authorisation Users can access objects belonging to other users #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 17

Slide 17

Broken Object Level Authorisation Users can access objects belonging to other users • User can access another user’s resource • Changing an ID or key allows access to privileged data #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 18

Slide 18

Broken Object Level Authorisation Examples • /users/123/orders - change to 124 and see someone else’s orders • /accounts/1/documents/999 checks the account, but not the document #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 19

Slide 19

Broken Object Level Authorisation Prevention • Implement proper authorisation based on user policies • Check if the user has access to the requested resource • Check that the operation is also allowed #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 20

Slide 20

Broken Object Property Authorisation Users can read or modify properties they shouldn’t #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 21

Slide 21

Broken Object Property Authorisation Users can read or modify properties they shouldn’t • Sending properties that this user shouldn’t see • Allowing this user to change a property they shouldn’t #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 22

Slide 22

Broken Object Property Authorisation Examples • User updates profile, includes “role”: “admin” in payload • Profile response includes PII that only admins should see #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 23

Slide 23

Broken Object Property Authorisation Prevention • Specifically choose object properties to return • Explicit allowlists for input properties #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 24

Slide 24

Rob Allen ~ akrabat.com

Slide 25

Slide 25

Exploiting how your API works Business logic and resource abuse Rob Allen ~ akrabat.com

Slide 26

Slide 26

Unrestricted resource consumption APIs that can be abused through resource consumption #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 27

Slide 27

Unrestricted resource consumption APIs that can be abused through resource consumption • Expensive operations without throttling • Exhausting memory through requests for too much data • Denial of service #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 28

Slide 28

Unrestricted resource consumption Examples • /widgets?page=1&per_page=1000000 • Resending an OTP that has no throttle; each SMS costs money #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 29

Slide 29

Unrestricted resource consumption Prevention • Rate limiting (per IP, per user, per endpoint) • Pagination with maximum limits • Resource quotas / Timeouts #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 30

Slide 30

Unrestricted access to business flows Critical workflows lack protection against automation #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 31

Slide 31

Unrestricted access to business flows Critical workflows lack protection against automation • Some business flows are more sensitive than others • Legitimate calls, but unexpected order • Excessive access may harm the business #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 32

Slide 32

Unrestricted access to business flows Examples • Ticket scalping bots, inventory hoarding • Book 90% of a hotel’s rooms, then cancel at the last minute #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 33

Slide 33

Unrestricted access to business flows Prevention • Device fingerprinting • Behavioural analysis • Transaction limits #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 34

Slide 34

Unsafe consumption of APIs Your API trusts third-party APIs too much #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 35

Slide 35

Unsafe consumption of APIs Your API trusts third-party APIs too much • Dependency on another’s vulnerabilities • Malicious data can be injected • Not accounting for failure #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 36

Slide 36

Unsafe consumption of APIs Examples • Geolocation API takes 30 seconds to time out and locks your API • Third-party API redirects your request to an attacker’s host #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 37

Slide 37

Unsafe consumption of APIs Prevention • Validate all external data • Whitelist redirect URLs • Implement timeouts #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 38

Slide 38

Rob Allen ~ akrabat.com

Slide 39

Slide 39

Operational security gaps Configuration and infrastructure vulnerabilities Rob Allen ~ akrabat.com

Slide 40

Slide 40

Security misconfiguration Insecure defaults and missing security hardening #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 41

Slide 41

Security misconfiguration Insecure defaults and missing security hardening • • • • Default configurations Missing security updates Unnecessary features enabled Header misconfiguration (CORS, etc.) #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 42

Slide 42

Security misconfiguration Examples • Error messages return stack traces • Access-Control-Allow-Origin:* on an authenticated endpoint #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 43

Slide 43

Security misconfiguration Prevention • Regular security auditing and updates • Audit and remove unnecessary features • For APIs against browser-based clients, implement CORS and security headers #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 44

Slide 44

Improper inventory management Do you know your API? #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 45

Slide 45

Improper inventory management Do you know your API? • Old API versions still running • Shadow APIs (undocumented endpoints) • Non-production environments accessible #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 46

Slide 46

Improper inventory management Examples • v1 API wasn’t decommissioned • Staging environment is public #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 47

Slide 47

Improper inventory management Prevention • Maintain API inventory/catalogue • API Gateway / automated discovery tools • Retire old versions with clear timelines #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 48

Slide 48

Server side request forgery API fetches remote resources without validation #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 49

Slide 49

Server side request forgery API fetches remote resources without validation • User-controlled URLs in API requests • API fetches a remote resource from a user-supplied URL • Can access internal network endpoints #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 50

Slide 50

Server side request forgery Examples • /images?url=http://127.0.0.1:8080/metrics #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 51

Slide 51

Server side request forgery Prevention • • • • Validate and sanitise URLs Whitelist for domains & media types, etc Disable HTTP redirection where possible Don’t send raw responses to clients #1 #2 #3 #4 #5 #6 #7 #8 #9 #10 Rob Allen ~ akrabat.com

Slide 52

Slide 52

In Closing Rob Allen ~ akrabat.com

Slide 53

Slide 53

OWASP API Security Top 10 • Authentication & authorisation failures • Business logic & resource abuse • Configuration & infrastructure vulnerabilities Rob Allen ~ akrabat.com

Slide 54

Slide 54

Security requires • Defence in depth • Testing with the mindset of an attacker • Ongoing attention Rob Allen ~ akrabat.com

Slide 55

Slide 55

Resources OWASP API Security Project website owasp.org/www-project-api-security/ REST Security Cheat Sheet cheatsheetseries.owasp.org/cheatsheets/REST_Security_Cheat_Sheet.h tml API Security news apisecurity.io Rob Allen ~ akrabat.com

Slide 56

Slide 56

“Securing APIs isn’t optional; it is the frontline defense for protecting data integrity and maintaining digital trust.” Randy Barr, Cequence Security Rob Allen ~ akrabat.com

Slide 57

Slide 57

Thank you! Rob Allen ~ akrabat.com