OWASP crAPI

OWASP crAPI - An OWASP incubator project

About OWASP crAPI

What is crAPI?

crAPI stands for “Completely Ridiculous API”. It simulates an API-driven, microservice-based web application that is a platform for vehicle owners. Following in the footsteps of Webgoat and JuiceShop, crAPI is an intentionally vulnerable application. However, crAPI is primarily filled with API vulnerabilities for the purpose of teaching, learning, and practicing API security. You will not find the mundane XSS and SQLi challenges in crAPI. crAPI specializes in the common vulnerabilities that happen in modern API-based applications, including all those in the OWASP Top 10 for APIs. All the challenges in crAPI are based on real-life vulnerabilities that were found in APIs of big companies like Facebook, Uber, and Shopify. crAPI exposes many different vulnerabilities with a range of difficulties — some of them are easy to find, and others require multiple steps, brain cracking and creativity to exploit. Enjoy exploring and learning with crAPI!

Project Information

Incubator Project
Classification
Incubator
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.