Skill
API Security
AuthZ correctness, abuse controls, secure defaults.
Strong82%Evidence-first
Proficiency
6 capability3 tool2 working on
Capabilities
- Broken access control / IDOR preventionLabWriteup
- AuthN vs AuthZ separation (roles/scopes/claims)Writeup
- JWT/OAuth concepts + safe validationWriteup
- Rate limiting + abuse prevention patternsProject
- Audit-ready logging for auth + sensitive actionsProject
- Input validation strategy + safe error handlingProject
Tools
- Postman / InsomniaLab
- OpenAPI/Swagger (design + review)Writeup
- OWASP API Top 10 (reference)Writeup
Working On
- Advanced recon exposure checks (usernames/emails/leaks)Planned
- Auth abuse case library for demosPlanned
Next steps
This page will grow into proof blocks (labs, writeups, artifacts) as you attach evidence.