
APIs are the backbone of modern applications—but they also introduce unique security risks. In this hands-on workshop, participants will focus on the OWASP API Security Top Ten (2023).
Live Training $25 - $150
Course Length: 4 Hours
Includes a Certificate of Completion
Next scheduled date: September 19th, 2025 @ 11:30 AM EDT
Description
APIs are the backbone of modern applications—but they also introduce unique security risks. In this hands-on workshop, participants will focus on the OWASP API Security Top Ten (2023).
Using a “Bad, Better, Best” approach, they will analyze insecure API patterns, discuss mitigation techniques, and review improved code examples. Students can either download the code from the instructor’s GitHub repository to follow along on their own machines using VS Code or view the live walkthrough on the instructor’s screen.
System Requirements
-
Student/Lab Requirements:
- Modern operating system that can run VS Code (https://code.visualstudio.com/download), the ability to connect to the internet with a fastest enough speed for streaming, modern web browser installed, the ability to visit the streaming platform site and also GitHub.com. Please install VS Code before the class.
- Please install VS Code (or your IDE of preference, any will do) before the class and ensure you can visit the site GitHub.com
Syllabus
Introduction & Setup
-
- Brief overview of the workshop agenda
-
- Instructions for downloading code from GitHub
-
- Setting up VS Code and previewing the “Bad, Better, Best” examples
OWASP API Top Ten (Items 1-5)
-
- Brief overview of each item, its associated risks, and remediation
-
- Guided code review for each item:
-
- Bad: Reviewing an API with no defenses
-
- Better: Introducing one defense
-
- Best: Implementing multiple defenses
-
- Guided code review for each item:
-
- Open discussion: Key takeaways and questions
OWASP API Top Ten (Items 6-10)
-
- Brief overview of each item, its associated risks, and remediation
-
- Guided code review for each item:
-
- Bad: Reviewing an API with no defenses
-
- Better: Introducing one defense
-
- Best: Implementing multiple defenses
-
- Guided code review for each item:
-
- Open discussion: Lessons learned and practical applications
Wrap-Up & Q&A
-
- List of free and Open Source API Security Tools
-
- Conclusion and Questions
-
- Suggestions for continued learning and resources
FAQ
Security professionals looking to enhance their API security knowledge
Anyone responsible for designing, implementing, or maintaining API-based applications
Basic knowledge of coding and using VS Code
No prior API security experience is required
About the Instructor

Tanya Janca
Bio
Tanya Janca, aka SheHacksPurple, is the best-selling author of ‘Alice and Bob Learn Secure Coding’, ‘Alice and Bob Learn Application Security’ and the ‘AppSec Antics’ card game. Over her 28-year IT career she has won countless awards (including OWASP Lifetime Distinguished Member and Hacker of the Year), spoken all over the planet, and is a prolific blogger. Tanya has trained thousands of software developers and IT security professionals, via her online academies (We Hack Purple and Semgrep Academy), and her live training programs. Having performed counter-terrorism, led security for the 52nd Canadian general election, developed or secured countless applications, Tanya Janca is widely considered an international authority on the security of software.
Register for Upcoming
-
Filter by Product Instructor
-
Filter by Product Date
-
Filter by Product Type
Workshop: The OWASP API Security Top Ten 2023 with Tanya Janca
Complete Package
Live Training Tanya Janca
Virtual
Certificate of participation, six months access to class recordings and our appreciation.
Pay Forward What You Can
Live Training Tanya Janca
Virtual
Certificate of participation, six months access to class recordings and our appreciation.
Pay Forward What You Can
Live Training Tanya Janca
Virtual
Certificate of participation, six months access to class recordings and our appreciation.
Pay Forward What You Can
Live Training Tanya Janca
Virtual
Certificate of participation, six months access to class recordings and our appreciation.
Pay Forward What You Can
Live Training Tanya Janca
Virtual
Certificate of participation, six months access to class recordings and our appreciation.
Related products
-
Multiple InstructorsLive
Workshop: AI Foundation: Cyber Security Workflow Optimization using AI Technology with Joff Thyer and Derek Banks
View Course -
Multiple InstructorsLive
Workshop: Introduction to IP Network with John Strand
View Course This product has multiple variants. The options may be chosen on the product page -
Multiple InstructorsLive
Workshop: Introduction to Cloud Security with Beau Bullock
View Course -
Multiple InstructorsLive
Workshop: Intro to Virtualization with Daniel Lowrie
View Course This product has multiple variants. The options may be chosen on the product page