• Free

SOAPI Guide

  • Course
  • 8 Lessons

Map OpenAPI documentations as Neo4J graphs and uncover vulnerabilities in the design implementation of the API.

SOAPI helps you detect sensitive data exposure, public endpoint leaks and rate-limiting bypasses through graph traversal techniques - a Bloodhound for APIs.

The tool was developed and presented as part of OWASP Copenhagen 2024 and Disobey 2025 conferences - recordings coming soon!

This course provides a clear, step-by-step guide to install, configure and run SOAPI.

Sign-up for free below!

visualisation

Graph representation of OpenAPI documentation generated by SOAPI

Contents

Lessons

0x01 - Intro
0x02 - Installation
0x03 - Scanning
0x04 - Visualisation
0x05 - Sensitive Objects
0x06 - Public Data
0x07 - Rate Limit Bypass

Resources

OWASP 2024