CAPIE · API Pentesting Labs

Labs for the Certified API Pentesting Industry Expert course, in three tiers. Work them in order: drill each bug class on a naked lab, learn to hunt on a methodology lab, then prove it on a full exam-style API.

Tier 1 · Learn

Naked Labs

One tiny API, one vulnerability, one flag. Drill each OWASP API risk in isolation until the technique is automatic.

12 labs →
Tier 2 · Hunt

Methodology Labs

Realistic APIs full of legitimate features and decoys. Practice a repeatable method to find what's actually broken.

6 labs →
Tier 3 · Prove

Exam Labs

Full multi-vulnerability APIs, exam conditions. Enumerate the whole surface and capture every flag — no hand-holding.

3 labs →
Flags. Naked labs return flag{}; methodology and exam labs return CAPIE{} per finding. Each lab lives under its own path (e.g. https://capie.thexssrat.com/api01/) — hit it with curl, Postman, or Python. State resets on redeploy. Course: thexssrat.podia.com.