• Free

SOAPI Guide

  • Course
  • 8 Lessons

Map OpenAPI documentations as Neo4J graphs and uncover vulnerabilities in the design implementation of the API.

SOAPI helps you detect sensitive data exposure, public endpoint leaks and rate-limiting bypasses through graph traversal techniques - a Bloodhound for APIs.

The tool was developed and presented as part of OWASP Copenhagen 2024 and Disobey 2025 conferences - recordings coming soon!

This course provides a clear, step-by-step guide to install, configure and run SOAPI.

Sign-up for free below!

visualisation

Graph representation of OpenAPI documentation generated by SOAPI

Contents

Lessons

0x01 - Intro
  • 2 mins
  • 72.7 MB
0x02 - Installation
  • 8 mins
  • 140 MB
0x03 - Scanning
  • 3 mins
  • 102 MB
0x04 - Visualisation
  • 3 mins
  • 92 MB
0x05 - Sensitive Objects
  • 7 mins
  • 121 MB
0x06 - Public Data
  • 6 mins
  • 130 MB
0x07 - Rate Limit Bypass
  • 4 mins
  • 99.3 MB

Resources

OWASP 2024