Run this check →

New accounts start with 40 free credits.

Check an API against the OWASP API Security Top 10:2023

API Security — OWASP API Security Top 10:2023

Last updated: 29 September 2026

WHAT IT CHECKS

API code, specifications such as OpenAPI files, and configuration, against 81 rules covering all ten OWASP API Security Top 10:2023 categories — object, property and function level authorization; authentication; resource consumption; sensitive business flows; server-side request forgery; security misconfiguration; inventory management; and unsafe consumption of third-party APIs.

WHERE THE RULES COME FROM

OWASP's official API Security Top 10:2023 category pages, plus one NIST document.

WHAT IT DOES NOT CHECK

  • Not a penetration test. It reviews the code, specification and configuration; it does not call your API.

WHAT YOU GET BACK

  • Each gap it finds, with the rule it fails and the source text that rule was taken from, quoted, so you can check it yourself.
  • Replacement wording for each finding, and a corrected copy of your document to download.
  • The pack's declared gaps, printed on every report, so you know what was not checked.

HOW TO RUN IT

In the browser. Sign in at https://vera.ink/verify, paste or upload the document, and choose this pack. New accounts start with 40 credits; a check costs 3 credits up to about 4,500 words.

From your AI assistant. vera.ink is an MCP server. Connect it to Claude Code or Cursor and ask your assistant to check a file against this pack: https://vera.ink/developers

GOOD TO KNOW

  • vera.ink only reports findings it can tie to a rule in this pack, and quotes the source text so you can check it. Anything it can't tie to a rule is dropped from the report.
  • It is a review aid, not legal advice or a certification. Read each finding before you act on it.

More checks: https://vera.ink/check