DEV Community

API

Application Programming Interface

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
API Session Fixation Is Three Attacks, Not One — and Rotating Tokens Blocks None of Them

API Session Fixation Is Three Attacks, Not One — and Rotating Tokens Blocks None of Them

Comments
5 min read
NoSQL Injection in APIs: From Auth Bypass to JavaScript Execution via MongoDB Operators

NoSQL Injection in APIs: From Auth Bypass to JavaScript Execution via MongoDB Operators

Comments
5 min read
Non-Constant-Time Comparison Turns Every API Token into a Character-by-Character Oracle

Non-Constant-Time Comparison Turns Every API Token into a Character-by-Character Oracle

Comments
5 min read
Prompt Caching Is a Timing Oracle: How the 41-80% Cost Win Becomes Cross-Tenant System Prompt Extraction

Prompt Caching Is a Timing Oracle: How the 41-80% Cost Win Becomes Cross-Tenant System Prompt Extraction

Comments
4 min read
Stop Faking Your Test Data: Why `Faker.js` Breaks the Moment You Have Foreign Keys

Stop Faking Your Test Data: Why `Faker.js` Breaks the Moment You Have Foreign Keys

Comments
5 min read
One API Key Across OpenAI, Claude and Gemini: Chatbot Fallback Options for SaaS Apps

One API Key Across OpenAI, Claude and Gemini: Chatbot Fallback Options for SaaS Apps

Comments
7 min read
The most dangerous API response is HTTP 200 with an empty body

The most dangerous API response is HTTP 200 with an empty body

Comments
4 min read
3 API changes to audit before your next deploy: Supabase, HubSpot, and Shopify

3 API changes to audit before your next deploy: Supabase, HubSpot, and Shopify

Comments
3 min read
GraphQL APQ Registration Bypasses Query Allowlists and Introspection Controls

GraphQL APQ Registration Bypasses Query Allowlists and Introspection Controls

Comments
5 min read
Three Signal Channels Leak Valid Account Lists Before Authentication Completes: Status Code, Response Body, and Timing

Three Signal Channels Leak Valid Account Lists Before Authentication Completes: Status Code, Response Body, and Timing

Comments
5 min read
SSRF in APIs: Six URL-Accepting Parameter Types and the IMDSv1/IMDSv2 Decision That Determines Severity

SSRF in APIs: Six URL-Accepting Parameter Types and the IMDSv1/IMDSv2 Decision That Determines Severity

Comments
5 min read
A field disappeared from Shopify webhooks for two days and every monitor stayed green

A field disappeared from Shopify webhooks for two days and every monitor stayed green

Comments
9 min read
GraphQL in Production: Introspection, Alias Batching, and Rate Limit Bypass on Real APIs

GraphQL in Production: Introspection, Alias Batching, and Rate Limit Bypass on Real APIs

Comments
6 min read
API Token in Query Parameter: Six Places the Credential Persists Without You Knowing

API Token in Query Parameter: Six Places the Credential Persists Without You Knowing

Comments
5 min read
JWT kid Parameter Attacks: SQL Injection and Path Traversal via Key ID

JWT kid Parameter Attacks: SQL Injection and Path Traversal via Key ID

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.