# Why API Security is Critical?

Discover why API security is essential for modern applications. Explore the unique challenges, including business logic vulnerabilities, API evolution, and the difficulty of manual testing.

{% hint style="success" %}
**At a Glance**: 🛡️ API security is essential as APIs expose sensitive data and business functions. Traditional security measures can't keep up with their complexity, requiring automated, continuous and specialized tools like Pynt.
{% endhint %}

APIs are crucial for modern applications but are also prime targets for attackers. Without proper security, APIs can expose sensitive data and business functions, leading to serious breaches. 🛠️

## API Security is a Unique Challenge

* **Business Logic Vulnerabilities**: 💡 APIs often handle critical business functions, making them vulnerable to misuse.
* **Constant Evolution**: 🔄 APIs are frequently updated, introducing potential new vulnerabilities.
* **Public Exposure**: 🌐 APIs are often accessible online, providing easy access for attackers to backend systems.

***

## The OWASP API Security Top 10

The **OWASP API Security Top 10** highlights the most critical security risks specific to APIs. These risks include **broken object-level authorization**, **inadequate rate limiting**, and **insufficient logging and monitoring**, all of which can lead to severe breaches. APIs require dedicated security measures that address the unique ways APIs handle data and user interactions.

👉 Learn more from the [OWASP API Security Top 10](https://owasp.org/www-project-api-security/).

***

## Growing Attack Vectors: Large Language Models (LLMs)

The rise of **Large Language Models (LLMs)** like GPT-4 has introduced new risks for APIs. Attackers can use LLMs to generate malicious API calls at scale or identify patterns in API structures that could be exploited. APIs connected to LLMs are increasingly targeted due to the valuable data they process. This growing attack vector emphasizes the need for proactive, real-time API security to safeguard against AI-driven threats.

👉 Learn more from the [OWASP LLM Security Top 10](https://owasp.org/www-project-top-10-for-large-language-model-applications/).

{% hint style="warning" %}
The growing complexity of APIs and the introduction of LLM-based attack vectors make continuous, automated API security essential for modern businesses.
{% endhint %}

***

## Key Challenges in API Security

* **Manual Testing is Inefficient**: ⏳ Manually testing APIs is slow and can't keep up with evolving APIs.
* **False Positives Overload Teams**: 🧠 Traditional tools overwhelm security teams with false alerts.
* **Business Logic Focus**: 🔍 Many vulnerabilities come from how APIs handle business logic rather than technical flaws.
* **Shadow APIs**: 🕵️‍♂️ Undocumented APIs are often left unmonitored, presenting high risks.

{% hint style="info" %}
Automated, context-aware and dedicated tools are essential for keeping up with the fast-paced, evolving API security landscape.
{% endhint %}


# Pynt at a Glance

Learn how Pynt automates API security with contextual analysis, real-world attack simulations, API discovery, and continuous monitoring.

{% hint style="success" %}
**At a Glance**: 🚀 Pynt automates API security testing with real-world attack simulations, contextual analysis for accurate vulnerability detection, discovers undocumented APIs, and integrates seamlessly into your CI/CD pipeline for continuous protection.
{% endhint %}

Pynt is a cutting-edge API security platform that automates vulnerability detection using **context-aware attack simulations**. Its **contextual analysis** makes it more precise by understanding how APIs function within specific environments, leading to fewer false positives and more relevant findings.

## Key Features

* **Shift-Left Security**: 🕒 Introduces security early in the development lifecycle, enabling developers to detect vulnerabilities before production.
* **Contextual Analysis for Attack Simulation**: 🔍 Pynt analyzes the context of your API traffic, understanding the unique behavior of your APIs. This results in more accurate attack simulations tailored to your specific environment.
* **Business Logic Security**: 🔒 Pynt identifies vulnerabilities related to business logic that conventional tools often miss.
* **Continuous Monitoring**: 🔄 Integrates with CI/CD pipelines for ongoing, automated API security checks.
* **Comprehensive API Discovery**: 📚 Automatically discovers shadow and undocumented APIs through the **API catalog** feature, ensuring no API endpoint is left unmonitored.

***

## Pynt's Major Components

Pynt consists of two main components:

1. **Pynt Security Tests**: These are deployed via a container and can be run locally or in the CI/CD pipeline. This is part of Pynt's [free Starter Plan](https://www.pynt.io/pricing) and is accessible via [www.pynt.io](https://www.pynt.io). Designed for running automated security scans.
2. **Pynt SaaS**: A centralized platform that allows security owners to manage all APIs and scans in one place. Available with the [Business Plan](https://www.pynt.io/pricing), this component is accessible via [app.pynt.io](https://app.pynt.io).

***

### Who Should Use It?

{% hint style="info" %}
💡 **Pynt Security Tests**: Ideal for **security owners but also developers**, **testers**, **DevSecOps** teams who need to run automated API security scans, either locally leveraging Pynt from their existing tools or within CI/CD pipelines.
{% endhint %}

{% hint style="info" %}
💡 **Pynt SaaS**: Designed for **security owners** who want a unified view of all APIs, scan results, and the ability to manage and monitor the security testing process across their organization.
{% endhint %}

***

## How Pynt Security Testing Works

Pynt captures and analyzes your API traffic to simulate **real-world attacks**. Using its **contextual analysis**, Pynt verifies the success of attacks, ensuring highly accurate results with minimal false positives. This tailored approach helps to catch real vulnerabilities while avoiding unnecessary alerts.

#### Coverage Includes:

* **OWASP API Security Top 10**: Targeting critical risks in APIs like broken object-level authorization and excessive data exposure. [Learn more](https://owasp.org/www-project-api-security/)
* **OWASP Top 10 for Web Applications**: Identifying common web vulnerabilities, including injection and broken authentication. [Learn more](https://owasp.org/www-project-top-ten/)
* **OWASP Top 10 for LLMs**: Addressing new risks posed by large language models interacting with APIs. [Learn more](https://owasp.org/www-project-top-10-for-large-language-model-applications/)

{% hint style="info" %}
By automating both security testing and API discovery with contextual analysis, Pynt provides comprehensive coverage, ensuring that your APIs meet industry-standard security benchmarks.
{% endhint %}

👉 [**Get started with integrating Pynt into your CI/CD**](/documentation/security-testing-integrations/pynt-on-ci-cd)**.**

<figure><img src="/files/1ewl9l2bpULxD1vZN1gG" alt=""><figcaption><p><a href="/pages/hSFiKgobe8gp7EOdc8TB"><em>Github Actions example</em></a></p></figcaption></figure>

👉 [**Get started with building your API Catalog**](/documentation/api-catalog/api-catalog-overview)

<figure><img src="/files/Cv5Qv1OGBfBUMCKz4pFq" alt=""><figcaption><p><em>Pynt's Catalog</em></p></figcaption></figure>


# Who Should Use Pynt?

Pynt is designed for Application Security Engineers, Developers, and DevSecOps teams. Automate API security testing, discover undocumented APIs, and reduce false positives.

{% hint style="success" %}
**At a Glance**: 👩‍💻 Pynt is designed for Application Security Engineers, Developers, and DevSecOps teams. Automate API security testing, reduce false positives, and discover undocumented APIs to ensure complete coverage.
{% endhint %}

Pynt is a versatile tool for teams responsible for API security throughout the development lifecycle, especially in **Application Security**, **Development**, and **DevSecOps** roles. 🛠️

***

## Application Security Engineers

Security engineers tasked with protecting APIs benefit from Pynt’s automated, context-aware testing capabilities. Pynt allows them to:

* **Automate Manual Processes**: 🔧 Reduce the workload by automating vulnerability detection with Pynt.
* **Focus on Verified Vulnerabilities**: 🔍 Minimize false positives, enabling teams to focus on real threats.
* **Tool Integration**: ⚙️ Pynt works with tools AppSec engineers already use, such as Burp Suite.

***

## Developers and Testers

With API security shifting left, developers are increasingly responsible for securing the code they write. Pynt helps developers by:

* **Integrating Security into CI/CD**: 🧑‍💻 Seamlessly integrate API security testing into your CI/CD workflows.
* **Tool Integration**: ⚙️ Pynt integrates easily with Postman, Selenium, and many other API testing tools.

***

## DevSecOps Teams

DevSecOps teams need continuous security testing across the entire development lifecycle. Pynt supports DevSecOps by:

* **Automating Security**: 🔄 Continuous security testing without disrupting the development process.
* **Cross-Team Collaboration**: 🤝 Pynt facilitates collaboration between development, security, and operations teams by integrating into the CI/CD pipeline.


# Security Testing Overview

Get a comprehensive overview of security testing in Pynt. Understand how Pynt's advanced tools help identify vulnerabilities, assess risks, and secure your APIs effectively.

{% hint style="success" %}
🔥 Pynt's API Security Testing is fully available for **Business plan users**, and limited for **Starter plan users** (up to 10 API endpoints) 🆓.
{% endhint %}

## How Does Pynt Work?

Pynt leverages an **integrated shift-left approach** and **unique hack technology** using home-grown attack scenarios to:

* Detect real vulnerabilities 🔍
* Discover APIs 📚
* Suggest fixes for verified vulnerabilities 🛠️

{% hint style="info" %}
Pynt acts like a hacker: It deeply analyses normal API traffic to build a model and then generates simulated attacks, verifies if the attack succeeds, and determines whether your API is vulnerable.
{% endhint %}

***

## Why Use Your Functional Tests?

Unlike other platforms (e.g., fuzzing), Pynt uses traffic from your functional tests to create real attack scenarios. This approach allows Pynt to:

* Perform tests with **no configuration**, running in minutes ⚡.
* Provide an **accurate overview of vulnerabilities** with **near-zero false positives** 🎯.
* Leverage functional tests for **maximum API coverage**, as tests evolve with your APIs 🔄.

<figure><img src="/files/gjooGp9RIan99aQWyzQF" alt=""><figcaption><p>Pynt's testing flow</p></figcaption></figure>

## Getting Started

{% hint style="info" %}
🔗 **Get started with Pynt’s API Security Testing**: Pynt’s security engine goes beyond conventional measures, leveraging your existing API functional tests for proactive testing.
{% endhint %}

#### To get started quickly with Pynt, we recommend the following steps:

1. **Follow the** [**Prerequisites** ](/documentation/api-security-testing/prerequisites-for-running-pynt-scans)📋
2. **Run a single scan** - start directly from [here](https://docs.pynt.io/documentation/api-security-testing/www.pynt.io) or choose from the supported integrations [below](#available-integrations)🔍
3. **Integrate Pynt with your** [**CI/CD pipeline**](/documentation/security-testing-integrations/pynt-on-ci-cd) for continuous coverage 🔄&#x20;

***

### Available integrations&#x20;

Pynt leverages a sophisticated context-aware security engine that goes beyond conventional measures. By leveraging your existing tools and functional tests, it conducts proactive API security tests directly from your local machine:

* Get started with [**API testing tools**](/documentation/security-testing-integrations/pynt-with-api-testing-tools) 🛠️
* Get started with [**API testing CLIs**](/documentation/security-testing-integrations/pynt-with-api-testing-clis) 🖥️
* Get started with [**API testing frameworks**](/documentation/security-testing-integrations/pynt-with-testing-frameworks) ⚙️
* Get started with [**Burp Suite**](/documentation/security-testing-integrations/pynt-with-burp-suite) 🔍
* Get started with [**Browser testing**](/documentation/security-testing-integrations/pynt-with-browsers) 🌐

***

### Integrate API Security Testing Into Your CI/CD

{% hint style="success" %}
🔐 **Power of Continuous API Pentesting in CI/CD**: Integrating API security testing into your CI/CD pipeline ensures vulnerabilities are detected early in the development lifecycle.
{% endhint %}

We recommend to add Pynt into your CI/CD for continuous monitoring for API Security vulnerabilities. \
Pynt API security testing suite seamlessly integrates into existing development tools and CI/CD workflows.&#x20;

👉 [**Get started with integrating Pynt into your CI/CD**](/documentation/security-testing-integrations/pynt-on-ci-cd)**.**

<figure><img src="/files/1ewl9l2bpULxD1vZN1gG" alt=""><figcaption><p><a href="/pages/hSFiKgobe8gp7EOdc8TB"><em>Github Actions example</em></a>:</p></figcaption></figure>


# Prerequisites for Running Pynt Scans

Discover the prerequisites needed to seamlessly onboard with Pynt.

{% hint style="success" %}
**At a Glance**: 🛠️ Before running Pynt scans, ensure your environment is correctly set up with the required system configurations, permissions, and tools for a smooth and successful API security scan.
{% endhint %}

## System Requirements

* **Docker Installed & Running**: If you're running Pynt locally, ensure Docker is installed and running. [Install Docker here](https://docs.docker.com/engine/install/).
* **Python Installed**: If using Pynt locally, make sure Python is installed on your machine. minimum Python version: **3.9**
* **GHCR Image Access**: Ensure you can pull images from the [GHCR repository](https://github.com/pynt-io/pynt).

{% hint style="info" %}
If you have trouble pulling images, follow the steps provided in the guide for accessing the public registry.
{% endhint %}

## Network Access

* **Pynt Domain Accessible**: Verify that [**app.pynt.io**](https://app.pynt.io) is reachable from the machine running Pynt.

## Integration with Postman

* **Postman Installed**: If you're integrating [Pynt with Postman](/documentation/security-testing-integrations/pynt-with-api-testing-tools/pynt-for-postman), ensure you're using the Postman app (note: Pynt requires Docker access and doesn’t support the Postman web interface).

## Functional Tests

* **Functional Tests Required**: For several integrations, Pynt uses your existing functional tests (Postman, Newman, CLI) to drive its security scans. Ensure your functional test collection is available, your environment variables are set, and the target application is running.
* Ensure everything is working by **running your functional tests against the target application** before executing Pynt’s security tests.

{% hint style="info" %}
🔧 **Pro tip**: Pynt utilizes your functional tests to inform the security tests it runs. The broader and more comprehensive your functional tests, the more security coverage Pynt will provide. More APIs, users, and requests mean richer security testing!
{% endhint %}


# How to Install Pynt CLI

Learn how to install the Pynt container for seamless API security testing. Follow our quick guide to set up and deploy Pynt in your environment.

{% hint style="success" %}
**At a Glance**: 🚀 Learn how to install the Pynt container for seamless API security testing in a few simple steps. This guide covers everything from setting up Pynt CLI to running your first Pynt scan.
{% endhint %}

## Introduction

Installing the Pynt container is a straightforward process, enabling you to set up and deploy comprehensive API security testing in your environment. Whether you're integrating Pynt into CI/CD pipelines or running it standalone, follow these steps to get Pynt up and running smoothly.

{% hint style="info" %}
💡 **Why Pynt's Container is Needed**: Pynt's container allows you to run Pynt from any location, supporting deployment in local or on-premises. It ensures Pynt is available for API security testing in flexible setups. However, for **Postman**, there’s an option to run **Pynt directly from the SaaS platform**, eliminating the need to install a container. If you prefer this option, you may skip this section.
{% endhint %}

***

## Install Pynt CLI

Pynt is deployed as a **Python-based CLI**. To install the Pynt CLI, simply use `pip`:

```bash
python3 -m pip install pyntcli
```

{% hint style="info" %}
📥 **Tip**: Ensure Python 3 is installed before running the above command!
{% endhint %}

***

## Running Pynt for the First Time

On the first time running Pynt CLI you will need to authenticate with Pynt:

<figure><img src="/files/12HthtcDPV2DSS77a1Ri" alt="" width="301"><figcaption><p>First login with Pynt CLI</p></figcaption></figure>

Once authenticated, the CLI will not ask for authentication again. You won’t need to log in again unless your session expires.

***

## Do I Need to Pull the Pynt Docker Image?

No. Pynt will handle anything for you!

{% hint style="info" %}
🛠️ **No manual docker operations are needed!** The Pynt CLI automatically manages all Docker operations, including pulling the latest image and running the container.
{% endhint %}


# How to install Pynt Binary (Linux only)

Learn how to install the Pynt binary for seamless API security testing. Follow our quick guide to set up and deploy Pynt in your environment.

Pynt Binary can be used in Linux based CI/CD environments where docker cannot be used, its syntax compatible to Pynt CLI.

PYNT\_ID must be exported as an environment variable as Pynt authentication is not implemented yet

[How to get PYNT\_ID](/documentation/security-testing-integrations/pynt-on-ci-cd/how-to-get-pynt-id-for-ci-cd-authentication)

1. **Get the install script:**&#x20;

```bash
wget https://cdn.pynt.io/binary-release/install.sh
chmod +x install.sh
```

1. **Run the Install Script**:
   * Execute the `install.sh` script to install `pynt`:

     ```
     ./install.sh
     ```
2. **Installation Steps**:
   * The `install.sh` script performs the following steps:
     * Creates the `.pynt/bin` and `.pynt/results` directories in the user's home directory.
     * Copies the `pynt`, `newman`, `mitmdump`, and `custom_har.py` files to the `.pynt/bin` directory.
     * Creates a symlink to the `pynt` binary in `/usr/local/bin` for easy access.

**Note**: Ensure you run the `install.sh` script as a non-root user. If the symlink creation fails, you may need to create it manually or run `pynt` from the `.pynt/bin` directory.


# Pynt CLI Modes

Explore Pynt's CLI modes for API security testing, learn how these modes integrate with your tools and workflows to perform comprehensive security scans.

Pynt offers two powerful modes within its CLI for conducting API security tests: [**Pynt Command**](#pynt-command) and [**Pynt Listen**](#pynt-listen). Each mode is designed to integrate with various tools and workflows, ensuring flexibility in how API security tests are performed.

***

### Pynt Command

{% hint style="info" %}
💡 **Pynt Command Mode**: Pynt Command allows users to wrap their existing CLI-based functional tests with Pynt’s security testing capabilities. It seamlessly integrates into your current workflow, enabling automatic API security testing alongside functional tests.
{% endhint %}

Pynt Command supports a wide range of configurations and optional arguments to tailor the tests to specific needs, making it adaptable for various testing environments.

***

### Pynt Listen

{% hint style="info" %}
💡 **Pynt Listen Mode**: Pynt Listen operates as an interactive proxy, listening on a specified port and capturing network traffic for security analysis. It is designed for tools that can direct their traffic through a proxy, providing flexibility for API security testing in various scenarios.
{% endhint %}

With Pynt Listen, users can capture traffic from a variety of sources and initiate security tests by triggering the scan, making it ideal for capturing real-time data from browsers, testing suites, and more.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Pynt Command CLI Mode

Leverage Pynt in Command CLI mode for efficient, automated API security testing. Run comprehensive security scans directly from your command-line interface.

{% hint style="success" %}
🚀 **At a Glance**:

* **Pynt Command Mode**: Run automated API security tests alongside your CLI-based functional tests, integrating security seamlessly into your workflow.
  {% endhint %}

The Pynt command is a mode within the Pynt CLI that enables you to run API security tests seamlessly alongside any CLI-based functional tests. It integrates directly into your existing testing workflow without requiring changes to your test scripts.

To use the Pynt command, simply wrap your existing functional test command with pynt. This allows Pynt to intercept and analyze API traffic generated by your tests in real time, automatically identifying potential security issues.

## Basic usage

```bash
pynt command --cmd <your command line>
```

## Optional arguments

{% code overflow="wrap" fullWidth="true" %}

```bash
    --cmd - The command that runs the functional tests
    --captured-domains - Pynt will scan only these domains and subdomains. For all domains write "*"
    --test-name - A name for your Pynt scan
    --port - Set the port pynt will listen to (DEFAULT: random)
    --allow-errors - If present will allow command to fail and continue execution
    --ca-path - The path to the CA file in PEM format
    --proxy-port - Set the port proxied traffic should be routed to (DEFAULT: 6666)
    --report - If present will save the generated report in this path.
    --insecure - Use when target uses self signed certificates
    --self-signed - Use when the functional test verify SSL
    --no-proxy-export - Pynt will not export the proxy settings to the environment
    --application-id - Attach the scan to an application, you can find the ID in your applications area at app.pynt.io
    --application-name - Attach the scan to an application, application will be created automatically if it does not exist.
    --host-ca - Path to the CA file in PEM format to enable SSL certificate verification for pynt when running through a VPN.
    --severity-level - 'all', 'medium', 'high', 'critical', 'none' (default) 
    --tag - Tag the scan. Repeat for multiple tags
    --verbose - Use to get more detailed information about the run
```

{% endcode %}

## Examples

* [Pynt with pytest](/documentation/security-testing-integrations/pynt-with-testing-frameworks/pynt-for-pytest)
* [Pynt with Rest Assured](/documentation/security-testing-integrations/pynt-with-testing-frameworks/pynt-for-rest-assured)
* [Pynt with Jest](/documentation/security-testing-integrations/pynt-with-testing-frameworks/pynt-for-jest)
* [Pynt with curl](/documentation/security-testing-integrations/advanced-pynt-examples/pynt-with-curl)
* [Pynt with ReadyAPI testrunner](/documentation/security-testing-integrations/pynt-with-api-testing-clis/pynt-for-testrunner-readyapi-cli)

#### How Pynt command works

<figure><img src="/files/EXbaNvNbvvWK7VG0MqOz" alt=""><figcaption><p>Pynt command architecture</p></figcaption></figure>

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Pynt Listen CLI Mode

Leverage Pynt in Listen CLI mode to monitor and secure your API traffic in real-time. Automate security testing directly from your command-line interface.

{% hint style="success" %}
🚀 **At a Glance**:

* **Pynt Listen Mode**: Capture real-time API traffic through a proxy for in-depth security analysis, perfect for tools that generate network requests.
  {% endhint %}

**Pynt Listen** is an interactive feature in Pynt that acts as a listening proxy on a chosen port. It's designed to capture network traffic when users redirect it to this port. Pynt stays in listening mode, waiting for the user's cue. A scan on the captured traffic starts when the user presses enter, moving Pynt from waiting to actively analyzing the traffic.

Pynt can be integrated with nearly any tool that generates API traffic, provided the tool can direct its traffic through Pynt's proxy.

## Basic usage

```bash
pynt listen --captured-domains <domains to scan>
```

## Required arguments

{% code overflow="wrap" %}

```
--captured-domains - Pynt will scan only these domains and subdomains. For all domains write "*"
```

{% endcode %}

Specifying a captured domain is crucial when using `pynt listen`, particularly for web applications. Web browsers often generate a vast amount of unrelated traffic, which can clutter the scan results. By focusing on a specific domain, `pynt listen` can more effectively monitor relevant network activity.

## Optional arguments

{% code overflow="wrap" %}

```bash
    --port - Set the port pynt will listen to (DEFAULT: 5001)
    --ca-path - The path to the CA file in PEM format
    --proxy-port - Set the port proxied traffic should be routed to (DEFAULT: 6666)
    --report - If present will save the generated report in this path.
    --insecure - use when target uses self signed certificates
    --host-ca - path to the CA file in PEM format to enable SSL certificate verification for pynt when running through a VPN.
    --return-error - 'all-findings' (warnings, or errors), 'errors-only', 'never' (default),
```

{% endcode %}

**Examples**

* [Pynt with browsers](/documentation/security-testing-integrations/pynt-with-browsers)
* [Pynt with Burp suite](https://docs.pynt.io/documentation/api-security-testing/pynt-cli-modes/pages/doVs4aTeXMxywcY5yjCG#id-2.-use-pynt-listen-as-an-upstream-proxy-of-burp)
* [Pynt with ReadyAPI](/documentation/security-testing-integrations/pynt-with-api-testing-tools/pynt-for-readyapi)
* [Pynt with Insomnia](/documentation/security-testing-integrations/pynt-with-api-testing-tools/pynt-for-insomnia)

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Pynt Security Tests Coverage

The following page describe the updated security test coverage by Pynt

{% hint style="success" %}
**At a Glance**: 🔐 Pynt offers comprehensive API security testing by leveraging real-world attack simulations and homegrown tests. It addresses key risks highlighted in the **OWASP Top 10** while continuously enhancing its security scope.
{% endhint %}

## Pynt Security Tests Coverage - Introduction

Pynt's security tests cover a wide range of vulnerabilities using **real-world attack simulations** and **homegrown attack scenarios**, ensuring robust API security. These tests align with:

* [**OWASP Top 10 for APIs**](https://owasp.org/www-project-api-security/): Tackling API-specific risks like broken authentication and data exposure.
* [**OWASP Top 10 for Web Applications**](https://owasp.org/www-project-top-ten/): Covering general web vulnerabilities such as injection attacks.
* [**OWASP Top 10 for LLMs**](https://owasp.org/www-project-top-10-for-large-language-model-applications/): Addressing emerging threats in large language models.

Pynt goes beyond the **OWASP Top 10**, offering **homegrown tests** that identify gaps often missed by standard tools. These unique tests bolster your API's security by providing extra protection against potential threats. Learn more at [Pynt vs OWASP: Pynt’s Top-10 Focus](https://www.pynt.io/resources-hub/guides-and-reports/pynt-vs-owasp-pynt-top-10-api-vulnerabilties), for detailed insights.

***

Pynt continuously evolves to provide maximum security coverage. Pynt integrates seamlessly into your CI/CD pipeline, ensuring high accuracy and minimal false positives while safeguarding critical endpoints.

## Pynt Test Cases

{% hint style="info" %}
🛠️ **Note**: This list might be **partial** as it grows rapidly, so stay updated for expanded coverage!
{% endhint %}

<table><thead><tr><th width="397.33333333333326">Test case</th><th>Category</th><th data-hidden></th></tr></thead><tbody><tr><td><a href="/pages/3otspXtFJcpLC3jh12i1"><strong>[BL001]</strong></a> User data leakage to other users - Resource-ID authorization</td><td>Business Logic</td><td></td></tr><tr><td><a href="/pages/3otspXtFJcpLC3jh12i1"><strong>[BL002]</strong></a> User data leakage to other users - User-ID authorization</td><td>Business Logic</td><td></td></tr><tr><td><a href="/pages/3otspXtFJcpLC3jh12i1"><strong>[BL003]</strong></a> User data leakage to other users - Resource-ID and User-ID authorization</td><td>Business Logic</td><td></td></tr><tr><td><a href="/pages/3otspXtFJcpLC3jh12i1"><strong>[BL004]</strong></a> User data leakage to other users - credentials authorization</td><td>Business Logic</td><td></td></tr><tr><td><a href="/pages/3otspXtFJcpLC3jh12i1"><strong>[BL005]</strong></a> User data manipulation by other users - Resource-ID authorization</td><td>Business Logic</td><td></td></tr><tr><td><a href="/pages/3otspXtFJcpLC3jh12i1"><strong>[BL006]</strong></a> User data manipulation by other users - User-ID authorization</td><td>Business Logic</td><td></td></tr><tr><td><a href="/pages/3otspXtFJcpLC3jh12i1"><strong>[BL007]</strong></a> User data manipulation by other users - Resource-ID and User-ID authorization</td><td>Business Logic</td><td></td></tr><tr><td><a href="/pages/3otspXtFJcpLC3jh12i1"><strong>[BL008]</strong></a> User data manipulation by other users - credentials authorization</td><td>Business Logic</td><td></td></tr><tr><td><a href="/pages/3otspXtFJcpLC3jh12i1"><strong>[BL009]</strong></a> Guessable resource identifier</td><td>Business Logic</td><td></td></tr><tr><td><a href="/pages/wrCKO6pI8KA7naPKnXLH"><strong>[INJ001]</strong> </a>SQL Injection</td><td>Injections</td><td></td></tr><tr><td><a href="/pages/wrCKO6pI8KA7naPKnXLH"><strong>[INJ002]</strong></a> MS-SQL Injection</td><td>Injections</td><td></td></tr><tr><td><a href="/pages/wrCKO6pI8KA7naPKnXLH"><strong>[INJ003]</strong></a> MySQL Injection</td><td>Injections</td><td></td></tr><tr><td><a href="/pages/wrCKO6pI8KA7naPKnXLH"><strong>[INJ004]</strong> </a>SQLite Injection</td><td>Injections</td><td></td></tr><tr><td><a href="/pages/wrCKO6pI8KA7naPKnXLH"><strong>[INJ005]</strong> </a>PostgreSQL Injection</td><td>Injections</td><td></td></tr><tr><td><a href="/pages/wrCKO6pI8KA7naPKnXLH"><strong>[INJ006]</strong></a> NoSQL Injection</td><td>Injections</td><td></td></tr><tr><td><a href="/pages/wrCKO6pI8KA7naPKnXLH"><strong>[INJ007]</strong></a> Command Injection</td><td>Injections</td><td></td></tr><tr><td><a href="/pages/wrCKO6pI8KA7naPKnXLH"><strong>[INJ008]</strong></a> Server-side template injection</td><td>Injections</td><td></td></tr><tr><td><a href="/pages/63ebGl1HhF3RZTdFZ9Wy"><strong>[AB001]</strong></a> Ignored authentication token</td><td>Authentication bypass</td><td></td></tr><tr><td><a href="/pages/63ebGl1HhF3RZTdFZ9Wy"><strong>[AB002]</strong></a> No signature validation in JWT</td><td>Authentication bypass</td><td></td></tr><tr><td><a href="/pages/63ebGl1HhF3RZTdFZ9Wy"><strong>[AB003]</strong></a> JWT hashed without secret</td><td>Authentication bypass</td><td></td></tr><tr><td><a href="/pages/63ebGl1HhF3RZTdFZ9Wy"><strong>[AB004]</strong> </a>No signature in JWT</td><td>Authentication bypass</td><td></td></tr><tr><td><a href="/pages/63ebGl1HhF3RZTdFZ9Wy"><strong>[AB005]</strong></a> Unsigned JWT</td><td>Authentication bypass</td><td></td></tr><tr><td><a href="/pages/w9OVIVQpG6hVwkVJx7na"><strong>[MA001]</strong></a> Mass assignment by manipulation of hidden attributes</td><td>Mass Assignment</td><td></td></tr><tr><td><a href="/pages/w9OVIVQpG6hVwkVJx7na"><strong>[MA002]</strong></a> Mass assignment by flag overloading</td><td>Mass Assignment</td><td></td></tr><tr><td><a href="/pages/TBPL93bDzPfYAD1m5msz"><strong>[SSRF001]</strong> </a>Local file access</td><td>Server-Side request forgery</td><td></td></tr><tr><td><a href="/pages/d2szORBHLzyhLhLye6rb"><strong>[ST001]</strong></a> Stack trace in response</td><td>Stack trace in response</td><td></td></tr><tr><td><a href="/pages/xSo8qBAJAvp6C0yggKKM"><strong>[RES001]</strong></a> Resources limiting</td><td>Lack of Resources and Rate Limiting</td><td></td></tr><tr><td><a href="/pages/Vqubcf9rbeO8cmFLRNqe"><strong>[FM001]</strong></a> File path manipulation</td><td>File path manipulation</td><td></td></tr><tr><td><a href="https://docs.pynt.io/documentation/api-security-testing/pynt-security-tests-coverage/graphql-introspection-vulnerability"><strong>[GQL001]</strong></a> GraphQL introspection</td><td>GraphQL introspection Vulnerability</td><td></td></tr><tr><td><strong>[</strong><a href="https://docs.pynt.io/documentation/api-security-testing/pynt-security-tests-coverage/graphql-alias-overloading"><strong>GQL002]</strong></a> GraphQL Alias Overloading</td><td>GraphQL Alias Overloading</td><td></td></tr><tr><td><a href="https://docs.pynt.io/documentation/api-security-testing/pynt-security-tests-coverage/llm-apis-vulnerabilities"><strong>[LLM001]</strong></a> Direct prompt injection</td><td>LLM APIs Vulnerabilities</td><td></td></tr><tr><td><a href="https://docs.pynt.io/documentation/api-security-testing/pynt-security-tests-coverage/llm-apis-vulnerabilities">[LLM002]</a> Prompt injection, alignment</td><td>LLM APIs Vulnerabilities</td><td></td></tr><tr><td><a href="https://docs.pynt.io/documentation/api-security-testing/pynt-security-tests-coverage/llm-apis-vulnerabilities"><strong>[LLM003]</strong></a> LLM Insecure output handling, type: XSS</td><td>LLM APIs Vulnerabilities</td><td></td></tr><tr><td><a href="https://docs.pynt.io/documentation/api-security-testing/pynt-security-tests-coverage/llm-apis-vulnerabilities"><strong>[LLM004]</strong></a> LLM Insecure output handling, type: SSRF</td><td>LLM APIs Vulnerabilities</td><td></td></tr><tr><td><a href="https://docs.pynt.io/documentation/api-security-testing/pynt-security-tests-coverage/llm-apis-vulnerabilities"><strong>[LLM005]</strong></a> LLM Insecure output handling, type:  Markdown</td><td>LLM APIs Vulnerabilities</td><td></td></tr><tr><td><a href="https://docs.pynt.io/documentation/api-security-testing/pynt-security-tests-coverage/insecure-transport-scheme"><strong>[TLS001]</strong></a> Insecure transport scheme</td><td>Insecure transport scheme</td><td></td></tr><tr><td><a href="https://docs.pynt.io/documentation/api-security-testing/pynt-security-tests-coverage/basic-authentication"><strong>[AB006]</strong></a> Basic Authentication</td><td>Basic Authentication</td><td></td></tr></tbody></table>


# Business Logic Tests

Uncover the details of Pynt's security tests for business logic vulnerabilities in our documentation! Learn how Pynt safeguards against critical business logic threats.

{% hint style="danger" %}
**At a Glance**: ⚠️ Business logic API attacks exploit weaknesses in the underlying logic of an API to gain unauthorized access or manipulate data. Developers must understand these issues to prevent security breaches.
{% endhint %}

***

## What are the common mistakes made by developers?

In most cases Business logic issues happen when authorization is not enforced through all the flows of the application. Modern applications usually assign a non guessable identifiers to users and resources.&#x20;

Consider the following example:

```python
def get_profile(self, getprofile_request, context):
    cursor, conn = connection_to_sql(f"GET_PROFILE_BL {getprofile_request}")
    cursor.execute('select * from profiles where uid=?',(getprofile_request.uid,))
    p = cursor.fetchone()
```

The function get\_profile accepts the User ID as uid and directly querying the database to get this user's profile without any validation that the logged in user is the same user that is represented by the uid.

## How can I fix Business Logic issues?

Ensure that only authorized users can access the API and that access is granted on a need-to-know basis. Use strong authentication methods such as multi-factor authentication and implement authorization checks at the API endpoint level.&#x20;

## Test cases in this category

These test cases test the enforce of authorization between user identifiers, resource identifiers and the actual logged in users on APIs that **read** user related data

<table><thead><tr><th>Test case</th><th width="226.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td><strong>[BL001]</strong> User data leakage to other users - Resource-ID authorization</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa1-broken-object-level-authorization.md">API1 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/285.html">CWE-285</a>, <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284</a>, <a href="https://cwe.mitre.org/data/definitions/639.html">CWE-639</a></td><td></td></tr><tr><td><strong>[BL002]</strong> User data leakage to other users - User-ID authorization</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa1-broken-object-level-authorization.md">API1 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/285.html">CWE-285</a>, <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284</a>, <a href="https://cwe.mitre.org/data/definitions/639.html">CWE-639</a></td><td></td></tr><tr><td><strong>[BL003]</strong> User data leakage to other users - Resource-ID and User-ID authorization</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa1-broken-object-level-authorization.md">API1 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/285.html">CWE-285</a>, <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284</a>, <a href="https://cwe.mitre.org/data/definitions/639.html">CWE-639</a></td><td></td></tr><tr><td><strong>[BL004]</strong> User data leakage to other users - credentials authorization</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa1-broken-object-level-authorization.md">API1 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/285.html">CWE-285</a>, <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284</a>, <a href="https://cwe.mitre.org/data/definitions/639.html">CWE-639</a></td><td></td></tr></tbody></table>

These test cases test the enforce of authorization between user identifiers, resource identifiers and the actual logged in users on APIs that **write** user related data

| Test case                                                                                  | OWASP                                                                                                                          | CWE                                                        |
| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------- |
| **\[BL005]** User data manipulation by other users - Resource-ID authorization             | [API5 OWASP Top 10](https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa5-broken-function-level-authorization.md) | [CWE-285](https://cwe.mitre.org/data/definitions/285.html) |
| **\[BL006]** User data manipulation by other users - User-ID authorization                 | [API5 OWASP Top 10](https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa5-broken-function-level-authorization.md) | [CWE-285](https://cwe.mitre.org/data/definitions/285.html) |
| **\[BL007]** User data manipulation by other users - Resource-ID and User-ID authorization | [API5 OWASP Top 10](https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa5-broken-function-level-authorization.md) | [CWE-285](https://cwe.mitre.org/data/definitions/285.html) |
| **\[BL008]** User data manipulation by other users - credentials authorization             | [API5 OWASP Top 10](https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa5-broken-function-level-authorization.md) | [CWE-285](https://cwe.mitre.org/data/definitions/285.html) |

This test case try to guess values of user Identifiers with a numeric structure

| Test case                                  | OWASP                                                                                                                          | CWE |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | --- |
| **\[BL009]** Guessable resource identifier | [API1 OWASP Top 10](https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa5-broken-function-level-authorization.md) |     |


# Injection Tests

Discover Pynt's documentation on security tests for injections! Learn how Pynt fortifies your APIs against injection vulnerabilities.

{% hint style="danger" %}
**At a Glance**: ⚠️ Injection flaws, such as SQL, NoSQL, and Command Injection, occur when untrusted data is sent to an interpreter as part of a command or query. Attackers can exploit these vulnerabilities to execute malicious commands or access unauthorized data.\
Source: [OWASP](https://owasp.org)
{% endhint %}

***

## What are the common mistakes made by developers?

Injection attacks happen when input from an API request is used directly in an operation such as DB query, system call, or a template without validating whether the input includes unwanted characters.&#x20;

## How can I fix Injection issues?

### SQL Injection

To prevent SQL injection attacks, consider the following measures:

1. Use parameterized queries: Parameterized queries allow you to separate the SQL query logic from the user-supplied data. Instead of concatenating user input directly into the SQL statement, you use placeholders in the SQL statement and pass the user input as parameters to the query. This prevents attackers from injecting malicious code into the SQL statement.

Example of parameterized query in Python:

```python
cursor.execute("SELECT * FROM users WHERE username = %s AND password = %s", (username, password))
```

2. Sanitize user input: Even with parameterized queries, it's important to sanitize user input to ensure that it conforms to expected values. This can include validating input format, data type, and length, as well as removing potentially harmful characters.

### NoSQL Injection

here's an example of a NoSQL injection vulnerability in a Node.js API that uses MongoDB as the database:

```javascript
const express = require('express');
const bodyParser = require('body-parser');
const mongodb = require('mongodb');

const app = express();
const mongoClient = mongodb.MongoClient;
const mongoUrl = 'mongodb://localhost:27017/mydb';

app.use(bodyParser.json());

app.post('/login', (req, res) => {
  const username = req.body.username;
  const password = req.body.password;

  mongoClient.connect(mongoUrl, (err, db) => {
    if (err) throw err;

    const users = db.collection('users');
    users.findOne({ username: username, password: password }, (err, user) => {
      if (err) throw err;

      if (user) {
        res.status(200).json({ message: 'Login successful' });
      } else {
        res.status(401).json({ message: 'Invalid username or password' });
      }

      db.close();
    });
  });
});

app.listen(3000, () => {
  console.log('API server started on port 3000');
});
```

In this example, the `POST /login` route accepts a JSON request body with a `username` and `password` field. The route queries the `users` collection in MongoDB to find a user with the specified credentials. If a matching user is found, the route returns a `200 OK` response with a success message. If no matching user is found, the route returns a `401 Unauthorized` response with an error message.

However, this API has a NoSQL injection vulnerability because it does not properly sanitize or validate the user input. An attacker can craft a specially-crafted JSON request body that bypasses the username and password check and allows them to log in as any user in the database.

For example, an attacker can send the following request body:

```json
{
  "username": { "$ne": "" },
  "password": { "$ne": "" }
}
```

This request body contains MongoDB operators (`$ne`) that instruct MongoDB to return any user document that has a non-empty `username` and `password` field. By doing so, the attacker can bypass the username and password check and log in as any user in the database.

To prevent NoSQL injection vulnerabilities, you should always sanitize and validate user input before using it in database queries.&#x20;

#### Command Injection

Here is an example of a command injection vulnerability in a Python Flask API:

```python
import subprocess
from flask import Flask, request

app = Flask(__name__)

@app.route('/ping')
def ping():
    host = request.args.get('host')
    result = subprocess.check_output(['ping', '-c', '1', host])
    return result

if __name__ == '__main__':
    app.run(debug=True)
```

In this example, the `GET /ping` route accepts a query parameter `host` and uses the `subprocess.check_output()` method to run the `ping` command on the specified host. However, this API has a command injection vulnerability because it does not properly validate or sanitize the user input. An attacker can craft a specially-crafted query parameter that injects arbitrary commands into the `ping` command and executes them on the server.

For example, an attacker can send the following request:

```bash
GET /ping?host=127.0.0.1; ls -la
```

This request injects the `ls -la` command into the `ping` command and lists the contents of the current directory on the server.

To prevent command injection vulnerabilities, you should always sanitize and validate user input before using it in command-line or shell operations.

### Template Injection

Here's an example of how template injection vulnerability can occur in an API:

Let's say you have an API that takes user input to generate a report. The report is generated using a template engine that allows users to inject their own variables into the template.

An attacker could exploit this vulnerability by injecting malicious code into the template engine. For example, suppose the attacker injects the following code into the template:

```python
{{7*'7'}}
```

If the template engine doesn't properly sanitize the input, it will execute the expression and return the result, which is `49`. However, if the attacker injects something more malicious, such as:

```lua
{{config.items()}}
```

This could allow the attacker to access and retrieve sensitive information about the server's configuration.

To prevent template injection vulnerabilities, it's important to always sanitize and validate user input before using it to generate templates. Additionally, it's important to limit the privileges of any code that executes within the context of the template engine to prevent attackers from executing arbitrary code on the server-side.

## Test cases in this category

<table><thead><tr><th>Test case</th><th width="226.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td><strong>[INJ001]</strong> SQL Injection (Generic)</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa8-injection.md">API8 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/89.html">CWE-89</a></td><td></td></tr><tr><td><strong>[INJ002]</strong> MS-SQL Injection</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa8-injection.md">API8 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/89.html">CWE-89</a></td><td></td></tr><tr><td><strong>[INJ003]</strong> MySQL Injection</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa8-injection.md">API8 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/89.html">CWE-89</a></td><td></td></tr><tr><td><strong>[INJ004]</strong> SQLite Injection</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa8-injection.md">API8 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/89.html">CWE-89</a></td><td></td></tr><tr><td><strong>[INJ005]</strong> PostgreSQL Injection</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa8-injection.md">API8 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/89.html">CWE-89</a></td><td></td></tr><tr><td><strong>[INJ006]</strong> NoSQL Injection</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa8-injection.md">API8 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/943.html">CWE-943</a></td><td></td></tr><tr><td><strong>[INJ007]</strong> Command Injection</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa8-injection.md">API8 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/77.html">CWE-77</a></td><td></td></tr><tr><td><strong>[INJ008]</strong> Server-side template injection</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa8-injection.md">API8 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/77.html">CWE-77</a></td><td></td></tr></tbody></table>

{% hint style="info" %}
💡 To learn more about injection flaws and how to prevent them, visit the [OWASP Injection Flows Page](https://owasp.org/www-community/Injection_Flaws).
{% endhint %}


# Authentication Bypass Tests

Delve into Pynt's documentation on authentication bypass security tests! Learn how Pynt ensures robust protection against authentication vulnerabilities.

{% hint style="danger" %}
**At a Glance**: 🚪 **Authentication Bypass Tests** focus on identifying vulnerabilities that allow unauthorized access to resources by bypassing authentication mechanisms. These tests ensure that API endpoints enforce proper authentication checks and prevent attackers from accessing sensitive data or functions without valid credentials.
{% endhint %}

***

## Introduction

Authentication bypass in API refers to a security vulnerability where an attacker is able to access an API endpoint or functionality without providing the necessary authentication credentials. This can happen due to various reasons such as:

1. Weak authentication mechanisms: If an API uses a weak authentication mechanism such as storing passwords in plain text, an attacker may be able to easily guess or obtain the credentials and bypass authentication.
2. Improper access control: If an API does not properly enforce access control rules, an attacker may be able to access sensitive resources or functionality without providing the required authentication credentials.
3. Exploiting vulnerabilities: If an API has vulnerabilities such as injection flaws or buffer overflows, an attacker may be able to exploit these vulnerabilities to bypass authentication and gain access to the API.

Authentication bypass can be a serious security risk as it allows attackers to access sensitive information or perform unauthorized actions.&#x20;

## What are the common mistakes made by developers?

A very common case for broken authentication is when the Authentication token validation is disabled for testing purposes and find its way to production code.

While JSON web tokens (JWTs) are widely used in modern application, sometimes developers use a weak validation function from the JWT library or even worse, implement the JWT validation function themselves. &#x20;

Consider the following vulnerability found and fixed in [jwt-simple](https://github.com/hokaccha/node-jwt-simple) library:

The function jwt\_decode accepted the JWT token and the key but not the expected hash algorithm, allowing an attacker to craft his own JWT with `"alg": "none"` in the algorithm header and the function will accept his token.

<figure><img src="/files/ssqIu3HvaUM8uHUPb1e2" alt=""><figcaption><p>jwt-simple vulnerability and the fix</p></figcaption></figure>

[More info about this vulnerability](https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/)

## How can I fix Authentication Bypass issues?

To prevent authentication bypass, APIs should implement strong authentication mechanisms, and enforce proper access control

## Test cases in this category:   &#x20;

This test case test the enforce of authentication token in authenticated request:

<table><thead><tr><th>Test case</th><th width="226.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td><strong>[AB001]</strong> Ignored authentication token</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa2-broken-user-authentication.md">API2 OWASP API Top 10</a></td><td>CWE-425, CWE-287, CWE-284, CWE-303</td><td></td></tr></tbody></table>

These test cases test for common flaws when JWTs are used for authentication:

<table><thead><tr><th>Test case</th><th width="226.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td><strong>[AB002]</strong> No signature validation in JWT</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa2-broken-user-authentication.md">API2 OWASP API Top 10</a></td><td>CWE-287, CWE-284, CWE-303</td><td></td></tr><tr><td><strong>[AB003]</strong> JWT hashed without secret</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa2-broken-user-authentication.md">API2 OWASP API Top 10</a></td><td>CWE-287, CWE-284, CWE-303</td><td></td></tr><tr><td><strong>[AB004]</strong> No signature in JWT</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa2-broken-user-authentication.md">API2 OWASP API Top 10</a></td><td>CWE-287, CWE-284, CWE-303</td><td></td></tr><tr><td><strong>[AB005]</strong> Unsigned JWT</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa2-broken-user-authentication.md">API2 OWASP API Top 10</a></td><td>CWE-287, CWE-284, CWE-303</td><td></td></tr></tbody></table>


# Mass Assignment Tests

Dive into Pynt's documentation on security tests for mass assignment vulnerabilities! Discover how Pynt safeguards against unauthorized access and manipulation of sensitive data.

{% hint style="danger" %}
**At a Glance**: 🛡️ **Mass Assignment Vulnerability** occurs when attackers manipulate or inject unexpected data into an API request, allowing them to modify data they shouldn’t have access to. This security issue arises when APIs accept and process more data fields than intended, often due to improper validation or filtering of input, leading to unauthorized data manipulation.
{% endhint %}

***

## What are the common mistakes made by developers?

This vulnerability typically arises when an API allows a client to submit multiple parameters in a single request, and those parameters can be used to update or create database records without validating that the request includes only the expected parameters. The attacker can exploit this by submitting additional parameters to the request, which are not validated by the API, allowing them to modify or create data in unintended ways.

One of the most well-known cases occurred in 2012, when a vulnerability was discovered in the Ruby on Rails web application framework, which allowed attackers to exploit mass assignment vulnerabilities in Rails-based applications.

The vulnerability was caused by the default behavior of Rails' mass assignment feature, which allowed developers to easily assign multiple attributes to a model object at once.

## How can I fix Mass Assignment issues?

Validate all input data, only accept the data that is necessary for the request, and ensure that the data is consistent with the intended operation, do not use one liners to blindly load all the parameters to an object. APIs can also use data binding techniques to map only the data that is explicitly allowed to be updated to the corresponding database fields, while ignoring the rest of the data in the request

## Test cases in this category:   &#x20;

This test case manipulates object properties from requests which the user should not have access to:

<table><thead><tr><th>Test case</th><th width="226.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td><strong>[MA001]</strong> Mass assignment by manipulation of hidden attributes</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa6-mass-assignment.md">API6 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/915.html">CWE-915</a></td><td></td></tr></tbody></table>

This test case manipulates boolean flags from requests that should not have access to these flags:

<table><thead><tr><th>Test case</th><th width="226.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td><strong>[MA002]</strong> Mass assignment by flag overloading</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa6-mass-assignment.md">API6 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/915.html">CWE-915</a></td><td></td></tr></tbody></table>


# Server-Side Request Forgery Tests

Explore Pynt's documentation on security tests for server-side request forgery! Learn how Pynt protects your APIs against this critical vulnerability.

{% hint style="danger" %}
**At a Glance**: 🌐 **SSRF (Server-Side Request Forgery)** occurs when an attacker tricks a server into making requests to unintended locations, such as internal systems or external third-party services. This vulnerability allows attackers to bypass firewall restrictions, access sensitive data, or execute malicious actions on behalf of the compromised server.
{% endhint %}

***

## Introduction

SSRF occurs when an attacker can manipulate the input parameters of a web application that requests resources from other servers, such as databases, web services, or other APIs.

The attacker can exploit this vulnerability to send forged requests to internal servers that are not meant to be exposed to the internet, such as backend systems or databases. This can result in unauthorized access, data theft, or other malicious activities that can compromise the security of the entire web application or the network it is hosted on.

## What are the common mistakes made by developers?

SSRF vulnerabilities occur due to a lack of input validation and inadequate access controls. Specifically, when applications allow untrusted input to be used in making requests to other servers, they can be exploited by attackers to manipulate these requests and send them to unintended targets

```python
import requests
from flask import Flask, request

app = Flask(__name__)

@app.route('/')
def index():
    url = request.args.get('url')
    response = requests.get(url)
    return response.text

if __name__ == '__main__':
    app.run(debug=True)
```

In this example, the Flask web application takes a URL parameter from the user and makes a GET request to that URL using the `requests` library. However, there is no input validation or sanitization being performed on the URL parameter, which means an attacker can pass in a malicious URL that points to an internal server or other restricted resource.

For example, an attacker could make a request like this:

```markup
http://localhost:5000/?url=http://192.168.0.1/secret
```

This would cause the web application to make a request to an internal server at IP address `192.168.0.1`, which may contain sensitive data or be otherwise restricted. By exploiting this SSRF vulnerability, the attacker could potentially gain access to this internal resource and compromise the security of the network.

## How can I fix SSRF issues?

Validate and sanitize user input before using it to make requests to external resources. One approach would be to use a whitelist of allowed URLs, or to restrict the URLs that can be accessed based on the user's permissions or role.

## Test cases in this category   &#x20;

This test case tries to manipulate a URL to access a local file on the server

<table><thead><tr><th>Test case</th><th width="226.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td><strong>[SSRF001]</strong> Local file access</td><td><a href="https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/">A10 OWASP top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/918.html">CWE-918</a></td><td></td></tr></tbody></table>


# Stack Trace In Response

Discover Pynt's documentation on security tests for stack trace in response vulnerabilities! Learn how Pynt secures your APIs against potential exposure of sensitive information.

{% hint style="danger" %}
**At a Glance**: 🛠️ **Stack Trace in Response** occurs when an application exposes its internal stack trace in the API response, revealing sensitive implementation details to attackers. This can give attackers valuable information about the application’s structure, libraries, and environment, making it easier to exploit vulnerabilities. It’s essential to remove or sanitize stack traces from responses in production environments to prevent exposing critical details.
{% endhint %}

***

## Introduction

A stack trace is a list of function calls that shows the flow of execution of a program. It can contain information about the names and locations of functions, variables, and parameters used in the code. If a stack trace is returned in an API response, it can reveal details about the server-side implementation of the API, including the programming language, framework, and libraries used, as well as the file path and line numbers of the code that threw the error.

Returning stack traces in API responses is generally not a good idea because it can expose sensitive information about your server and potentially compromise its security.

## What are the common mistakes made by developers?

There could be a few reasons why you are seeing stack traces returned by your API:

1. Some programming languages and frameworks have a "debug mode" which is used during development to help diagnose issues. When debug mode is enabled, stack traces may be returned in API responses. However, it's important to disable debug mode in production environments to prevent sensitive information from being exposed.
2. Error Handling: If your API is not handling errors correctly, it may be returning stack traces to clients. This can happen if your API is not configured to catch and handle exceptions in a way that prevents stack traces from being displayed.

## How can I fix returned stack trace issues?

It's important to ensure that your API is properly configured to handle errors and that stack traces are not returned to clients in production environments. You should also consider implementing custom error messages that provide enough information for clients to understand the problem without revealing sensitive information. This can help improve the security of your API and prevent potential attacks.

For example: to disable stack traces returned by Flask, you can set the `debug` configuration option to `False` in your Flask application. Here's an example:

```python
from flask import Flask

app = Flask(__name__)
app.config['DEBUG'] = False

# Your Flask routes and application code here
```

When `debug` is set to `True`, Flask will return detailed error messages including stack traces. By setting it to `False`, Flask will return a simpler error message that does not include a stack trace.

It's important to note that you should disable debug mode in production environments to prevent sensitive information from being exposed. In development environments, you can still use the stack trace for debugging purposes, but it should not be exposed to clients.

## Test cases in this category

This test case checks for stack traces returned in responses

<table><thead><tr><th>Test case</th><th width="226.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td><strong>[ST001]</strong> Stack trace in response</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa7-security-misconfiguration.md">API7 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/388.html">CWE-388</a></td><td></td></tr></tbody></table>


# Lack of Resources and Rate Limiting

Explore Pynt's comprehensive documentation on security tests for mitigating lack of resources and rate-limiting vulnerabilities! Learn how Pynt ensures robust protection against resource exhaustion.

{% hint style="danger" %}
**At a Glance**: 🛡️ **Resource Limit Vulnerability** occurs when an attacker causes an API to consume excessive resources, such as CPU, memory, or network bandwidth, beyond its intended capacity. This can lead to **Denial of Service (DoS)** attacks, where the API becomes unavailable or unresponsive due to resource exhaustion. Proper rate limiting and resource management are essential to prevent such attacks and ensure the stability of the API.
{% endhint %}

***

## What are the common mistakes made by developers?

Resource-limiting vulnerabilities in APIs can happen due to various reasons. Here are some common causes:

1. Lack of access controls: APIs may not have proper access controls in place to limit the number of requests per user or per IP address. This can allow attackers to send a large number of requests to the API and cause it to consume excessive resources.
2. Insufficient input validation: APIs may not properly validate input data from users, allowing attackers to send maliciously crafted data that can cause the API to consume excessive resources. For example, an attacker could send a request with a very large search query that causes the API to perform an extensive search operation.
3. Lack of resource allocation controls: APIs may not have controls in place to limit the amount of resources that can be consumed by each request. For example, an API endpoint may allow users to download large files without any restrictions on the file size or download speed.

## How can I fix lack of resources limiting issues?

&#x20;API designers should implement appropriate access controls, input validation, resource allocation controls, and optimize the code to reduce resource consumption. Additionally, they should monitor the API usage patterns and implement measures to handle unexpected traffic spikes and usage patterns.

## Test cases in this category:

This test case queries excessive number of elements

<table><thead><tr><th>Test case</th><th width="231.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td><strong>[RES001]</strong> Resources limiting</td><td><a href="https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa4-lack-of-resources-and-rate-limiting.md">API4 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/770.html">CWE-770</a></td><td></td></tr></tbody></table>


# File Path Manipulation

Explore Pynt's documentation on file path manipulation security tests! Understand how Pynt safeguards against file path vulnerabilities, ensuring robust security for your APIs.

{% hint style="danger" %}
**At a Glance**: 🗂️ **File Path Manipulation** occurs when an attacker alters the file path in an API request to access unauthorized files or directories on the server. This vulnerability, often called **directory traversal**, allows attackers to read, write, or execute files outside the intended directory. To prevent this, always validate and sanitize file paths, ensuring that only authorized files are accessed.
{% endhint %}

***

## Introduction

File path manipulation (sometimes called LFI - local file inclusion) is a type of security vulnerability that occurs when a cloud application allows an attacker to include files located on the server's local file system. This vulnerability typically arises when the application processes user-supplied input without proper validation or sanitization.

This vulnerability can have serious consequences as it allows an attacker to read sensitive files on the server. Some of the files that may be accessible through this vulnerability include configuration files, sensitive user data, and even system files, depending on the application's configuration and permissions.

## What are the common mistakes made by developers?

1. Insufficient input validation: Failing to properly validate user-supplied input allows attackers to manipulate file paths and inject malicious data that leads to file path attacks.
2. Using user-controlled input directly: Including user-controlled input, such as file names or paths, directly in file inclusion functions without proper sanitization can enable attacks.
3. Not using absolute file paths: Relying on relative file paths in file inclusion functions can create  vulnerabilities, as attackers may manipulate the relative paths to access unauthorized files.
4. Allowing directory traversal: Failing to restrict access to specific directories can enable attackers to traverse the directory structure and access sensitive files outside the intended scope.

## How can I fix file path manipulation issues?

1. Input Validation and Sanitization:
   * Always validate and sanitize user input before using it in file inclusion functions. Use whitelisting or regular expressions to ensure that input adheres to expected patterns.
   * Avoid using user-controlled input directly in file paths without proper validation.
2. Use Absolute File Paths:
   * Instead of relying on relative file paths, use absolute file paths when including files. This ensures that files are loaded from specific, predefined locations and prevents directory traversal attacks.
3. &#x20;Implement Access Controls:
   * Enforce access controls to restrict access to sensitive files and directories. Only allow access to files that are essential for the application's functionality and deny access to others.
4. Disable Remote File Inclusion:
   * If your application doesn't require it, disable the option to include files from remote servers. Remote file inclusion can be a security risk and should be avoided if not necessary.
5. Secure File Inclusion Functions:
   * If possible, use safer alternatives to file inclusion functions that provide additional security features. For example, some programming languages offer functions that automatically handle input sanitization and file inclusion securely.

## Test cases in this category

This test case queries excessive number of elements:

<table><thead><tr><th>Test case</th><th width="251.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td>[FM001] File path manipulation</td><td></td><td></td><td></td></tr></tbody></table>


# GraphQL Introspection Vulnerability

Explore Pynt's documentation on GraphQL Introspection security tests! Understand how Pynt safeguards your APIs against unintended exposure of schema details, ensuring robust security for your APIs.

{% hint style="danger" %}
**At a Glance**:  **GraphQL Introspection** allows clients to query the schema of a GraphQL API, revealing types, fields, queries, and mutations available on the backend. While this feature is beneficial during development, leaving introspection enabled in production can expose sensitive information to attackers. They can use this information to map out your API, discover hidden functionalities, deprecated fields, or potential weaknesses to exploit. To mitigate this risk, disable introspection in production or restrict it to authenticated and authorized users.
{% endhint %}

***

## Introduction

GraphQL Introspection is a powerful feature that enables clients to explore and understand the schema of a GraphQL API dynamically. By making special introspection queries, clients can retrieve detailed information about types, fields, arguments, and relationships within the API.  Although this feature is highly beneficial during development, leaving introspection enabled in production environments accessible to untrusted users can introduce significant security risks. Attackers can leverage introspection to gain deep insights into your API's structure, uncovering sensitive data or functionalities intended to be private or internal. This information can be used to craft targeted attacks, exploit vulnerabilities, or perform unauthorized operations.

## What are the common mistakes made by developers?

1. **Leaving Introspection Enabled in Production**: Developers often forget to disable introspection in production environments, allowing anyone to query the schema and discover sensitive details.
2. **Lack of Authentication and Authorization**: Allowing unauthenticated or unauthorized users to perform introspection queries exposes your API schema to potential malicious actors.

## How can I fix GraphQL Introspection issues?

Disable Introspection in Production

C**onfigure Your Server**:  Adjust your GraphQL server settings to disable introspection queries in production environments. Most GraphQL server implementations provide options to toggle this feature based on the environment.

#### Restrict Access to Introspection

**Implement Access Controls**: If disabling introspection entirely isn't feasible, restrict it to authenticated and authorized users.&#x20;

* ## Test cases in this category

This test case detect if GraphQL introspection is enabled:

<table><thead><tr><th>Test case</th><th width="251.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td>[GQL001] GraphQL introspection</td><td><a href="https://owasp.org/API-Security/editions/2023/en/0xa8-security-misconfiguration/">API8 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200</a></td><td></td></tr></tbody></table>


# GraphQL Alias Overloading

Explore Pynt's documentation on GraphQL Alias Overloading security tests! Understand how Pynt safeguards against alias overloading vulnerabilities, ensuring robust security for your APIs.

{% hint style="danger" %}
**At a Glance**:  **GraphQL Alias Overloading** occurs when an attacker abuses the alias feature in GraphQL queries to execute the same query multiple times within a single request by assigning different names to each. While aliases are designed for legitimate use cases, overloading them can lead to Denial of Service (DoS) attacks by overwhelming the server with redundant operations. To prevent this, implement query complexity limiting, depth limiting, and proper validation to ensure that only safe and efficient queries are processed
{% endhint %}

***

## Introduction

GraphQL Alias Overloading is a security vulnerability that arises when a client exploits the aliasing feature in GraphQL to execute the same query multiple times in a single request. By assigning different aliases to the same field or operation, an attacker can force the server to perform excessive processing, leading to high CPU and memory usage. This can ultimately result in a Denial of Service (DoS) attack, where legitimate users are denied access due to server overload.

For example, an attacker might send a query like:

```graphql
{
  user1: user(id: "123") { name }
  user2: user(id: "123") { name }
  user3: user(id: "123") { name }
  // ...repeated hundreds of times
}
```

In this scenario, the server processes the same `user` query multiple times under different aliases, consuming significant resources.

## What are the common mistakes made by developers?

1. **No Query Complexity Limitation**: Developers may fail to implement limits on query depth or complexity, allowing excessively nested or large queries to be processed.
2. **Unlimited Alias Usage**: Not restricting the number of aliases in a single query enables attackers to overload the server with redundant operations.
3. **Lack of Rate Limiting**: Without rate limiting, attackers can send numerous requests in a short time frame, exacerbating the impact of alias overloading.

## How can I fix GraphQL Introspection issues?

1. Restrict Alias Usage: Set limitations on the number of aliases permitted in a single request to minimize the potential for Denial of Service (DoS) attacks.
2. Enforce Rate Limiting: Implement controls to cap the number of requests a client can make within a certain time frame, thereby reducing the likelihood and impact of DoS attacks.

By implementing these measures, you can protect your GraphQL API from alias overloading attacks, ensuring it remains robust and reliable for legitimate users.

* ## Test cases in this category

This test case detect if GraphQL introspection is enabled:

<table><thead><tr><th>Test case</th><th width="251.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td>[GQL002] GraphQL Alias Overloading</td><td><a href="https://owasp.org/API-Security/editions/2023/en/0xa8-security-misconfiguration/">API8 OWASP API Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200</a></td><td></td></tr></tbody></table>


# LLM APIs Vulnerabilities

Discover Pynt's documentation on security tests for LLM (Large Language Model) injections! Learn how Pynt fortifies your APIs against LLM-based vulnerabilities.

{% hint style="danger" %}
**At a Glance**:  LLM vulnerabilities, such as **Prompt Injection** and **Insecure Output Handling**, occur when untrusted data is sent **to or from** a language model without proper validation or sanitization. Attackers can exploit these vulnerabilities to manipulate the behavior of the LLM, extract sensitive data, or execute malicious commands in downstream systems.
{% endhint %}

***

## What are the common mistakes made by developers?

LLM-based attacks happen when input from an API request is used directly in an LLM prompt or when outputs from an LLM are used directly in operations such as rendering HTML content, executing system calls, or interfacing with other services, without validating whether the input or output includes unwanted content.

## How can I fix LLM Injection issues?

#### Prompt Injection

To prevent prompt injection attacks, consider the following measures:

1. **Input Sanitization**: Always sanitize and validate user input before incorporating it into LLM prompts. Remove or escape any tokens or phrases that could alter the intended behavior of the LLM.
2. **Use Contextual Prompts**: Structure prompts to minimize the impact of injected content. For example, clearly separate system instructions from user-provided content.
3. **Limit LLM Instructions**: Avoid including system-level instructions in prompts that can be manipulated by user input.

#### Insecure Output Handling

Insecure Output Handling refers to the lack of adequate validation, sanitization, and management of outputs generated by large language models before they are passed downstream to other components and systems.

Exploiting an Insecure Output Handling vulnerability can lead to **XSS**, **CSRF**, and **Markdown injection** attacks in web browsers, as well as **SSRF**, **privilege escalation**, or **remote code execution** on backend systems.

**Example of Insecure Output Handling:**

Consider an API that uses an LLM to generate HTML content based on user input:

```python
from flask import Flask, request, render_template_string
from some_llm_library import generate_text

app = Flask(__name__)

@app.route('/generate', methods=['POST'])
def generate():
    topic = request.form.get('topic')
    prompt = f"Write an article about {topic}"
    content = generate_text(prompt)
    html = f"<html><body>{content}</body></html>"
    return render_template_string(html)

if __name__ == '__main__':
    app.run()
```

If the LLM generates malicious JavaScript code within `content`, it could lead to an XSS attack when rendered in the user's browser.

**How to Fix Insecure Output Handling:**

* **Sanitize LLM Outputs**: Use libraries to escape or remove potentially harmful content before rendering.
* **Set Content Security Policies**: Implement CSP headers to restrict the execution of scripts and other potentially dangerous content.

**Fixed Code Example:**

```python
from flask import Flask, request, render_template_string
from markupsafe import escape
from some_llm_library import generate_text

app = Flask(__name__)

@app.route('/generate', methods=['POST'])
def generate():
    topic = request.form.get('topic')
    prompt = f"Write an article about {escape(topic)}"
    content = generate_text(prompt)
    safe_content = escape(content)
    html = f"<html><body>{safe_content}</body></html>"
    return render_template_string(html)

if __name__ == '__main__':
    app.run()
```

#### Markdown Injection

Markdown content generated by LLMs can include embedded HTML or JavaScript, leading to XSS attacks when rendered.

**Vulnerable Example:**

```python
from flask import Flask, request, Markup
import markdown
from some_llm_library import generate_text

app = Flask(__name__)

@app.route('/post', methods=['POST'])
def post():
    topic = request.form.get('topic')
    prompt = f"Write a detailed post about {topic}"
    markdown_content = generate_text(prompt)
    html_content = markdown.markdown(markdown_content)
    return f"<html><body>{html_content}</body></html>"

if __name__ == '__main__':
    app.run()
```

An attacker could manipulate the LLM to generate malicious Markdown that includes scripts.

**Fixing Markdown Injection:**

* **Use Safe Markdown Renderers**: Utilize Markdown libraries that sanitize HTML content.
* **Sanitize After Rendering**: Escape or remove any HTML tags after converting from Markdown.

**Fixed Code Example:**

```python
from flask import Flask, request
import markdown
from bleach import clean
from some_llm_library import generate_text

app = Flask(__name__)

@app.route('/post', methods=['POST'])
def post():
    topic = request.form.get('topic')
    prompt = f"Write a detailed post about {topic}"
    markdown_content = generate_text(prompt)
    html_content = markdown.markdown(markdown_content)
    safe_html = clean(html_content)
    return f"<html><body>{safe_html}</body></html>"

if __name__ == '__main__':
    app.run()
```

#### Server-Side Request Forgery (SSRF) via LLM

An LLM might generate URLs or network requests based on user input, potentially leading to SSRF attacks.

**Vulnerable Example:**

```python
import requests
from flask import Flask, request, jsonify
from some_llm_library import generate_text

app = Flask(__name__)

@app.route('/fetch', methods=['POST'])
def fetch():
    query = request.json.get('query')
    prompt = f"Provide the URL for {query}"
    url = generate_text(prompt)
    response = requests.get(url)
    return jsonify({'data': response.text})

if __name__ == '__main__':
    app.run()
```

An attacker could manipulate the LLM to generate internal URLs, causing the server to make requests to internal services.

**Preventing SSRF:**

* **Validate and Sanitize URLs**: Ensure that the generated URLs point to allowed domains.
* **Implement Network Policies**: Restrict the server's network access to prevent unauthorized requests.

**Fixed Code Example:**

```python
import requests
from flask import Flask, request, jsonify
from urllib.parse import urlparse
from some_llm_library import generate_text

app = Flask(__name__)

ALLOWED_DOMAINS = ['example.com']

def is_allowed(url):
    domain = urlparse(url).netloc
    return domain in ALLOWED_DOMAINS

@app.route('/fetch', methods=['POST'])
def fetch():
    query = request.json.get('query')
    prompt = f"Provide the URL for {query} on example.com"
    url = generate_text(prompt).strip()
    if not is_allowed(url):
        return jsonify({'error': 'Disallowed domain'}), 400
    response = requests.get(url)
    return jsonify({'data': response.text})

if __name__ == '__main__':
    app.run()
```

***

By implementing these measures, you can significantly reduce the risk of LLM-related vulnerabilities in your APIs. Always treat both the input to and output from LLMs with the same caution as you would with any untrusted data.

* ## Test cases in this category

These test cases detect LLM APIs vulnerabilities:

<table><thead><tr><th>Test case</th><th width="251.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td>[LLM001] Direct prompt injection</td><td><a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-slides-v1_0.pdf">LLM01 OWASP LLM Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/1426.html">CWE-1426</a></td><td></td></tr><tr><td>[LLM002] Prompt injection, alignment</td><td><a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-slides-v1_0.pdf">LLM01 OWASP LLM Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/1426.html">CWE-1426</a></td><td></td></tr><tr><td>[LLM003] Insecure output handling, type: XSS</td><td><a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-slides-v1_0.pdf">LLM02 OWASP LLM Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/1426.html">CWE-1426</a>, <a href="https://cwe.mitre.org/data/definitions/94.html">CWE-94</a></td><td></td></tr><tr><td>[LLM004] Insecure output handling, type: SSRF</td><td><a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-slides-v1_0.pdf">LLM02 OWASP LLM Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/1426.html">CWE-1426</a>, <a href="https://cwe.mitre.org/data/definitions/94.html">CWE-94</a></td><td></td></tr><tr><td>[LLM005] Insecure output handling, type: Markdown</td><td><a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-slides-v1_0.pdf">LLM02 OWASP LLM Top 10</a></td><td><a href="https://cwe.mitre.org/data/definitions/1426.html">CWE-1426</a>, <a href="https://cwe.mitre.org/data/definitions/94.html">CWE-94</a></td><td></td></tr></tbody></table>


# Insecure Transport Scheme

Explore Pynt's documentation on insecure transport scheme vulnerabilities! Understand how Pynt safeguards against unsecured communication protocols, ensuring robust security for your APIs.

{% hint style="danger" %}
**At a Glance**: 🔓 **Insecure Transport Scheme** vulnerabilities occur when an API or service communicates over unsecured protocols like HTTP instead of enforcing secure alternatives like HTTPS. This vulnerability allows sensitive data to be transmitted in an unencrypted format, making it susceptible to interception, tampering, and eavesdropping. To prevent this, always enforce secure protocols for all communications to protect data integrity and confidentiality.
{% endhint %}

***

## Introduction

An insecure scheme vulnerability arises when a cloud application, web application or API uses unsecured communication protocols, such as HTTP, which do not encrypt data transmitted between the client and the server. This lack of encryption means that any data sent over the network—including sensitive information like authentication tokens, personal data, and API keys—can be intercepted and read by malicious actors.

Insecure schemes not only compromise confidentiality but also the integrity of the data. Attackers can perform man-in-the-middle attacks, intercepting communications between the client and server to modify or inject malicious content. This can lead to unauthorized access, data breaches, and other security incidents.

## What are the common mistakes made by developers?

1. **Not Enforcing HTTPS:**

   Failing to enforce the use of HTTPS, allowing clients to connect over unsecured HTTP by default.
2. **Mixed Content:**

   Including resources (like scripts, images, or stylesheets) over HTTP in an HTTPS page, leading to mixed content vulnerabilities.
3. **Lack of HTTP Strict Transport Security (HSTS):**

   Not implementing HSTS headers to enforce HTTPS connections, allowing attackers to downgrade connections to HTTP.
4. **Using Outdated Protocols and Cipher Suites:**

   Employing outdated encryption protocols like SSLv2, SSLv3, or weak cipher suites that are vulnerable to attacks.

## How can I fix file path manipulation issues?

**Enforce HTTPS:**

* Redirect HTTP to HTTPS:
  * Configure your server to automatically redirect all HTTP requests to HTTPS.

**Secure Resource Loading:**

* Use HTTPS for All Resources:
  * Ensure that all resources (images, scripts, stylesheets) are loaded over HTTPS to prevent mixed content warnings and vulnerabilities.
* Avoid Protocol-Relative URLs:
  * Use absolute HTTPS URLs instead of `//example.com/resource.js`.

**Implement HSTS (HTTP Strict Transport Security):**

* Add HSTS Headers:
  * Include the `Strict-Transport-Security` header in your server responses to enforce HTTPS connections for all future requests.
* Preload HSTS:
  * Submit your domain to HSTS preload lists used by browsers for added security.

**Proper Certificate Management:**

* Use Valid SSL/TLS Certificates:
  * Obtain certificates from trusted Certificate Authorities (CAs).
* Regular Renewal:
  * Monitor certificate expiration dates and renew them timely.

**Disable Insecure Protocols and Cipher Suites:**

* Update Server Configuration:
  * Disable outdated protocols like SSLv2, SSLv3, and TLS 1.0.
* Enable Strong Cipher Suites:
  * Use modern cipher suites that support forward secrecy.

## Test cases in this category

This test case queries excessive number of elements:

<table><thead><tr><th>Test case</th><th width="251.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td>[TLS001] Insecure transport scheme</td><td><a href="https://owasp.org/Top10/A02_2021-Cryptographic_Failures/">A02  Cryptographic Failures</a></td><td><a href="https://cwe.mitre.org/data/definitions/319.html">CWE-319</a>, <a href="https://cwe.mitre.org/data/definitions/523.html">CWE-523</a>, <a href="https://cwe.mitre.org/data/definitions/720.html">CWE-720</a>, <a href="https://cwe.mitre.org/data/definitions/818.html">CWE-818</a></td><td></td></tr></tbody></table>


# Basic Authentication

Explore Pynt's documentation on Basic Authentication! Understand how Pynt safeguards against insecure authentication methods, ensuring robust security for your APIs.

{% hint style="danger" %}
**At a Glance**: **Basic Authentication** poses a security risks because it transmits credentials encoded in Base64, which is not encryption but merely encoding. Moreover, the credentials (username and password) are sent with every API request, increasing the risk of interception and exposure. Basic Authentication also lacks permissions granularity, making it difficult to enforce fine-grained access control. To prevent these issues, avoid using Basic Authentication and adopt more secure authentication methods like OAuth2 or token-based authentication to protect sensitive data and user accounts.
{% endhint %}

***

## Introduction

Basic Authentication is an HTTP authentication method where user credentials (username and password) are concatenated with a colon, encoded in Base64, and included in the `Authorization` header of every HTTP request. This means that the credentials are repeatedly transmitted over the network, increasing the chances that they could be intercepted if the connection is not secure.

The primary concern with Basic Authentication is that Base64 encoding is not a secure way to transmit sensitive information. Base64 can be easily decoded, meaning that if the HTTP request is intercepted—especially over an insecure connection like HTTP—the credentials can be read by anyone monitoring the network traffic. This vulnerability can lead to unauthorized access, data breaches, and other security incidents.

Furthermore, Basic Authentication lacks permissions granularity. It does not support fine-grained access control, making it challenging to assign different permissions or roles to different users. This can result in users having more access than necessary, violating the principle of least privilege and increasing the potential impact of compromised credentials.

## What are the common mistakes made by developers?

1. **Using Basic Authentication over Insecure Channels:**
   * Sending credentials over HTTP instead of HTTPS, making them susceptible to interception.
2. **Assuming Base64 Encoding is Secure:**
   * Believing that Base64 encoding provides security when it's merely an encoding scheme, not encryption.
3. **Transmitting Credentials with Every Request:**
   * Including the username and password in every API call increases the risk of credential exposure.
4. **Lack of Permissions Granularity:**
   * Failing to implement fine-grained access controls, leading to overly broad permissions for users.
5. **Storing Credentials Insecurely:**
   * Saving encoded credentials in insecure locations like logs or configuration files without proper protection.
6. **Lack of Multi-Factor Authentication (MFA):**
   * Relying solely on Basic Authentication without additional authentication factors increases risk.
7. **Not Rotating Credentials:**
   * Failing to change passwords regularly, which can lead to prolonged exposure if credentials are compromised.
8. **Ignoring Account Lockout Policies:**
   * Not implementing lockout mechanisms after multiple failed login attempts, making brute-force attacks easier.
9. **Insufficient Monitoring and Logging:**
   * Not adequately monitoring authentication attempts, which can delay the detection of unauthorized access.

## How can I fix file path manipulation issues?

#### Avoid Using Basic Authentication:

* **Adopt More Secure Methods:**
  * Use authentication protocols like OAuth2, OpenID Connect, or JWT (JSON Web Tokens) that offer enhanced security features and support for permissions granularity.

#### Use HTTPS for All Communications:

* **Encrypt Data in Transit:**
  * Ensure all API calls are made over HTTPS to encrypt the data between the client and server.
* **Enforce HTTPS:**
  * Configure the server to redirect all HTTP requests to HTTPS and use HSTS (HTTP Strict Transport Security).

## Test cases in this category

This test case queries excessive number of elements:

<table><thead><tr><th>Test case</th><th width="251.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td>[AB006] Basic Authentication</td><td><a href="https://owasp.org/API-Security/editions/2023/en/0xa8-security-misconfiguration/">API8:2023</a></td><td><a href="https://cwe.mitre.org/data/definitions/309.html">CWE-309</a></td><td></td></tr></tbody></table>


# HTTP Desynchronization (Desync) Attack

Explore Pynt's documentation on HTTP desynchronization security tests! Understand how Pynt identifies and mitigates desync vulnerabilities to ensure robust protection for your APIs.

{% hint style="danger" %}
**At a Glance**: 🔄 HTTP De-synchronization (Desync) Attack\
A de-synchronization vulnerability occurs when servers or components in an API ecosystem interpret HTTP requests inconsistently, especially regarding headers like `Content-Length` and `Transfer-Encoding`. This mismatch allows attackers to "smuggle" malicious requests through the front-end server to the back-end server without detection. These attacks can lead to unauthorized actions, data leakage, or even denial of service. To mitigate these risks, ensure strict validation and uniform interpretation of HTTP headers across all components.
{% endhint %}

***

## Introduction

HTTP de-synchronization (commonly known as HTTP request smuggling) is a security vulnerability that exploits inconsistencies in how HTTP requests are parsed by front-end and back-end servers. When a server interprets the boundaries of HTTP requests differently, attackers can inject a malicious payload that is processed by one server but hidden from another.

This vulnerability can lead to various outcomes, such as bypassing security controls, extracting sensitive data, or disrupting the application's normal behavior. It typically arises in API gateways, proxies, or load balancers that handle HTTP traffic between components.

## What are the common mistakes made by developers?

1. **Inconsistent Parsing of HTTP Headers**:\
   Failing to enforce uniform interpretation of HTTP headers like `Content-Length` and `Transfer-Encoding` between front-end and back-end servers.
2. **Allowing Ambiguous Headers**:\
   Accepting ambiguous or conflicting headers, such as requests containing both `Content-Length` and `Transfer-Encoding`, without resolving conflicts.
3. **Neglecting Request Queue Validation**:\
   Overlooking how request queues are processed by intermediary components, enabling attackers to smuggle additional requests.
4. **Trusting User-Supplied Input**:\
   Allowing unvalidated input in headers or payloads increases the risk of maliciously crafted requests.

## How can I fix HTTP desynchronization issues?

**Header Validation**

* Reject requests with ambiguous or conflicting headers (e.g., both `Content-Length` and `Transfer-Encoding` headers).
* Enforce strict validation of HTTP headers to ensure compliance with RFC standards.

**Uniform Parsing Rules**

* Ensure consistent interpretation of headers and request boundaries across all API components, including proxies, gateways, and back-end servers.

**Disable Chunked Encoding (if unnecessary)**

* If your application does not require `Transfer-Encoding: chunked`, disable it to minimize parsing complexity.

## Test cases in this category

This test case queries excessive number of elements:

<table><thead><tr><th>Test case</th><th width="251.33333333333331">OWASP</th><th>CWE</th><th data-hidden></th></tr></thead><tbody><tr><td>[MC001] HTTP Desync Attack</td><td><a href="https://owasp.org/API-Security/editions/2023/en/0xa8-security-misconfiguration/">API8:2023</a></td><td><a href="https://cwe.mitre.org/data/definitions/444.html">CWE-444</a></td><td></td></tr></tbody></table>


# Sensitive Data Exposure Detection

Detect and prevent sensitive data exposure with Pynt’s AI-powered analysis. Identify PII and data leaks across API environments with automated security testing and flow tracking.

## 🔍 Sensitive Data Flow

### At a Glance 🕵️‍♂️

Pynt automatically detects, tracks, and mitigates **sensitive data exposure** in APIs by leveraging **heuristic analysis, AI-driven pattern recognition, and contextual flow analysis**.

🚀 **Key Capabilities:**

* ✅ **AI-powered sensitive data detection** (PII, credentials, API keys, etc.)
* 🔗 **End-to-end data flow tracking** to highlight exposure risks
* 🛡 **Automated security testing** for improper data leaks
* 📊 **Actionable insights** for compliance & security hardening

***

### 🔎 How Pynt Detects Sensitive Data

#### 🧠 1. AI + Heuristics for Detection

Pynt automatically **classifies sensitive data** during API security scans using:\
🛠 **Predefined Heuristics** – Recognizing emails, credit card numbers, SSNs, API keys, tokens, etc.\
🤖 **AI-Driven Pattern Recognition** – Identifying variations of sensitive data that may pose risks.\
📡 **Contextual Understanding** – Analyzing API requests & responses to detect exposure.

💡 **Hint:** Sensitive data isn't just about what is exposed—it's also about **where** and **how** it's used!

***

#### 📡 2. Mapping Sensitive Data Flows

Beyond detection, Pynt evaluates **how** sensitive data is processed & transmitted:

🔍 **Traffic Analysis** – Monitoring API traffic (live & recorded) for leaks.\
🛤 **End-to-End Flow Tracking** – Mapping how sensitive data moves across endpoints.\
🚨 **Security Tests for Data Leaks** – Identifying misconfigurations & access control failures.

💡 **Hint:** API responses sometimes expose **more** data than needed. Pynt helps **reduce exposure** proactively! 🚀

***

#### 🛠 3. Shift-Left: Early Detection in Dev

Pynt integrates into CI/CD pipelines & API testing frameworks to **catch data leaks early**:

* 🔄 Detects **sensitive data exposure** in **Postman, Newman CLI, Burp, and CI/CD pipelines**.
* 📝 Generates **detailed reports** with exposed data types (**PII, HIPAA, PCI, financial data**).
* ⚡ Provides **actionable remediation insights** for dev & security teams.

💡 **Hint:** Shift-left security means **fixing issues before they reach production**! 🏗

***

### 🏆 Real-World Example: OWASP crAPI Scan

📌 **Case Study:** Pynt scanned OWASP crAPI (a vulnerable API application) and found:

📧 **Sensitive data leaks** in API responses (**emails, full names, VINs**).\
🔓 **Endpoints exposing private data** due to **missing access controls**.\
📊 **Unnecessary data exposure** that could be minimized for security.

🔗 **Example from Pynt Scan Report:**<br>

<figure><img src="/files/5IRCMgCSEykHLpJ6kh6r" alt=""><figcaption><p>Sensetive Data Snapshot Example from Pynt's Scan Report</p></figcaption></figure>

***

### 🎯 Why It Matters

🔹 **Protect user data & prevent compliance violations (GDPR, HIPAA, PCI DSS).**\
🔹 **Detect sensitive data leaks before attackers do!** 🛑\
🔹 **Integrate into your existing security & testing workflows.**

***


# Pynt Scans Troubleshooting

The following section refers to troubleshooting for running Pynt scans

{% hint style="success" %}
**At a Glance**: 🛠️ This troubleshooting guide helps resolve common issues encountered during API security scans with Pynt. From unreachable endpoints to missing test results and unexpected errors, follow these steps to resolve problems swiftly.
{% endhint %}

## Common Issues and Solutions

* **Unreachable Endpoints**: Ensure that the API endpoint is accessible and properly configured.
* **Authentication Issues**: Verify API authentication credentials.
* **Server-side Issues**: check server logs for details.
* **Missing Test Results**: Verify that all functional tests are set up correctly and integrated.
* **Unexpected Errors**: Check the error code explanations below for quick diagnosis.

***

## Ensuring Full Coverage

To ensure complete API security coverage:

* **Review Functional Tests**: More extensive tests mean broader security coverage.
* **Check API Visibility**: Ensure all endpoints are included in the scan.
* **Validate Test Inputs**: Confirm that all necessary environment variables and configurations are set.

{% hint style="info" %}
For more detailed solutions, check the detailed guide and to maximize your API security scans.
{% endhint %}

{% content-ref url="/pages/OdbX662Qw1teoDAIcvmU" %}
[Pynt CLI Troubleshooting](/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting)
{% endcontent-ref %}

{% content-ref url="/pages/be0PICClmjjEyoQpKfxC" %}
[Pynt for Postman Troubleshooting](/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-for-postman-troubleshooting)
{% endcontent-ref %}


# Pynt CLI Troubleshooting

Troubleshoot Pynt CLI effectively! Explore our documentation for insights and solutions to common issues you might encounter with Pynt's command-line interface.

{% hint style="success" %}
**At a Glance**: 🛠️ Encountering issues with Pynt CLI? This guide provides step-by-step solutions for resolving common problems from installation errors to scan execution issues, ensuring the smooth operation of your Pynt CLI.
{% endhint %}

***

## 'pynt' is not recognized

When you install Pynt CLI using `pip`, the output will show the path to the script folder. To prevent the "Pynt not recognized" error when running Pynt, ensure that the Python scripts folder is added to your PATH environment variable. This issue usually arises when the pip scripts folder is not included in your PATH.

<figure><img src="/files/rB4pT6dFq0SqjfpcQasg" alt=""><figcaption><p>Installing Pynt CLI</p></figcaption></figure>

To find Pynt location path after installation:

```bash
pip show pyntcli
```

<figure><img src="/files/mg81bSBlfbwHaDNa6alq" alt=""><figcaption><p>Path Location</p></figcaption></figure>

Add to PATH: [Instructions on how to add a variable to PATH for Win Mac and Linux](https://gist.github.com/nex3/c395b2f8fd4b02068be37c961301caa7)

***

## Wrong Pynt !

Getting the following message means that there is a conflict with another package named Pynt installed on your machine.

<figure><img src="/files/gMdltIMEu1CR5kgbv3do" alt=""><figcaption><p>Wrong Pynt !</p></figcaption></figure>

To remove the unwanted Pynt installation:

```bash
pip uninstall pynt
```

***

## Unable to pull the image from docker pull ghcr.io/pynt-io/pynt

If you're unable to pull the Pynt image from Docker, pull it manually and pynt will use the local image:

```bash
docker pull ghcr.io/pynt-io/pynt:v1-latest
```

#### Private registries:

If the Pynt image is mirrored to a private registry, override the image repository (`IMAGE`) and, if needed, the image tag (`TAG`).

```bash
# Override the image repository (without the tag)
export IMAGE=<private-image-repository-uri>
# Optional: Override the image tag
export TAG=<image-tag>

#Example:
export IMAGE=registry.company.com/security/pynt
export TAG=v1-latest
```

Visit [Pynt Docker Images](https://github.com/pynt-io/pynt/pkgs/container/pynt) for available tags and more information.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Pynt for Postman Troubleshooting

Resolve Postman integration hiccups with ease! Check out our troubleshooting guide for Pynt Postman integration.

{% hint style="success" %}
**At a Glance**: 🛠️ If you're facing challenges using [Pynt with Postman](/documentation/security-testing-integrations/pynt-with-api-testing-tools/pynt-for-postman), this troubleshooting guide will help you resolve common issues for seamless integration and effective API security testing in your Postman environment.
{% endhint %}

<figure><img src="/files/hw9FimenUcradPb4o8Mi" alt=""><figcaption></figcaption></figure>

## **Common error messages**

<table><thead><tr><th width="283">Issue</th><th>Error Message</th></tr></thead><tbody><tr><td><a href="/pages/ebLz9NXDMzn7sTcYDmM9">Pynt container not running </a></td><td>Pynt container is not running</td></tr><tr><td><a href="/pages/YCk7hQWFRN8hEl612536">Empty API key </a></td><td>The API key provided is empty, please provide a valid API key</td></tr><tr><td><a href="/pages/z38qJ1ywmBAeGpNnR31B">Unauthorized API key</a></td><td>The API key provided was unauthorized, either your API key is invalid or we encountered a network issue.</td></tr><tr><td><a href="/pages/t8TLHAHhXBFWqML2dJtF">Collection not found</a></td><td>Unable to fetch collection, please make sure a valid collection/environment was provided</td></tr><tr><td><a href="/pages/qnr9X36pG1ewY4o6xDQg">Non-unique collection name</a></td><td>More than one collection with the same name was found - please provide a unique collection name or collection id</td></tr><tr><td><a href="/pages/HpiqFcfaohogh8nmJxFp">Empty collection identifier </a></td><td>The collection identifier provided in the Pynt configuration under "YOUR-COLLECTION" is malformed</td></tr><tr><td><a href="/pages/mRVaNjsoAzDXDXyXP7Pi">Unreachable target</a></td><td>We identified that your target is unreachable. Please make sure your target is up and running.  </td></tr><tr><td><a href="/pages/HfwlXbiS86OT6Jeisyz6">Target responds with errors</a></td><td>All responses from your functional test collection run returned with errors, please check your collection vs. the target</td></tr><tr><td><a href="/pages/Jefbc5tBl4dswJDvoh0i">Unresolved Target Domain</a></td><td>The target domain was unresolved. Please make sure your functional tests use the correct domain</td></tr><tr><td><a href="/pages/s19dOiF5bhGuruyuBYcp">Unresolved Variable</a></td><td>The functional tests had an unresolved variable. Check that the environment file is included</td></tr><tr><td><a href="/pages/DRqsGMIx3UhURfYc4TCc">TLS Handshake Fail</a></td><td>TLS handshake failed because your target uses a self-signed certificate.</td></tr></tbody></table>

## **Common warning messages**

<table><thead><tr><th width="286">Issue</th><th>Warning message</th></tr></thead><tbody><tr><td><a href="/pages/uSk2OitsifvrKkMKJM0N">Few requests</a></td><td>We identified only X requests. Adding more requests will provide better security test coverage</td></tr><tr><td><a href="/pages/oZIsQ15rqYiEzZKKBmkm">One user only</a></td><td>The functional tests included only one user. Adding more users will allow Pynt to run more accurate tests</td></tr><tr><td><a href="/pages/FuaiTAq4XUNPRnNlVunx">Failed assertions</a></td><td>The functional tests had assertions that failed, which affected the security tests. Fixing these assertions will improve the security tests</td></tr></tbody></table>


# Troubleshoot Pynt Container not Running Error

Troubleshoot issues with your Pynt container not running. Learn common causes and solutions to get your Pynt container up and running smoothly.

{% hint style="success" %}
**At a Glance**: 🚀 If your Pynt container isn't running as expected, this guide helps identify and resolve the most common issues. Follow these steps to ensure your Pynt container is operational for smooth API security testing.
{% endhint %}

***

## Pynt Container is Not Running

### What Happened?

Pynt container was not able to run.

### How to Resolve?

1. **Check Docker**: Ensure **Docker Desktop** is installed, available, and running on your machine.
2. **Install Pynt CLI**: If not already installed, use `pip` to install Pynt CLI:

   ```bash
   python -m pip install pyntcli
   ```
3. **Run Pynt in Postman Mode**: Start Pynt in **Postman mode**:

   ```bash
   pynt postman
   ```

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Empty API Key Error

Resolve issues related to an empty API key in Pynt. Learn how to identify and fix problems with missing or unconfigured API keys.

{% hint style="success" %}
**At a Glance**: 🔑 Encountering an empty API key in Pynt can prevent scans from running properly. This guide helps troubleshoot and resolve issues related to missing or unconfigured API keys, ensuring your Pynt setup is ready for secure API testing.
{% endhint %}

***

## The API Key Provided is Empty

### What Happened?

Pynt Postman API key provided to Pynt is empty.

### How to Resolve?

1. **Get Your API Key**: Retrieve your API key from **Postman** [here](https://postman.co/settings/me/api-keys).
2. &#x20;**Configure Pynt Collection**: Copy and paste the key into the **current value** column in Pynt collection variables.
3. &#x20;**Save Your Configuration**: Click **Save** or use `Ctrl + S`.

{% hint style="info" %}
Make sure the API key is correctly configured before running scans to ensure proper functionality.
{% endhint %}

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Unauthorized API Key Error

Fix unauthorized API key issues in Pynt. Learn how to troubleshoot and resolve problems with API key permissions to ensure smooth operation.

{% hint style="danger" %}
**At a Glance**: ❌ Receiving an "Unauthorized API Key" error in Pynt means your API key lacks the necessary permissions. Follow these steps to resolve the issue and ensure your API key is properly authorized for API testing.
{% endhint %}

***

## Error: The API key provided was unauthorized

### What Happened?

The API key you supplied was rejected by **Postman**.

### How to Resolve?

1. **Use a Valid API Key**: Ensure the API key has not expired by checking here.
2. **Check for Whitespace**: Ensure no trailing white spaces (e.g., carriage returns) are left at the end of the key.
3. **Network Restrictions**: This error may occur if your network passes through a **TLS-terminating VPN**, preventing Pynt from reaching Postman.

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Collection Not Found Error

Troubleshoot "Collection Not Found" errors in Pynt. Learn how to identify and resolve issues related to missing or incorrectly referenced collections.

{% hint style="danger" %}
**At a Glance**: ⚠️ A "Collection Not Found" error in Pynt means the specified collection is missing or incorrectly referenced. Follow these steps to troubleshoot and resolve the issue.
{% endhint %}

***

## Error: There is no collection in the workspace by the name provided

### What Happened?

Pynt was not able to find a test collection with this name.

### How to Resolve?

1. **Verify Collection Exists**: Ensure the collection with the supplied name or ID exists in your workspace.
2. **Check for Whitespace**: Make sure there is no extra whitespace (such as a carriage return) in the collection name.
3. **Save Changes**: Confirm that all changes were saved using the **"Save"** button in the Postman UI.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Non-Unique Collection Name Error

Resolve non-unique collection name issues in Pynt. Learn how to troubleshoot and correct duplicate collection names to avoid conflicts in API testing.

{% hint style="danger" %}
**At a Glance**: ⚠️ This error in Pynt occurs when there are duplicate collection names in Postman, causing conflicts during testing. Follow this guide to resolve the issue by ensuring each collection has a unique name.
{% endhint %}

***

## Error: More than one collection with the same name was found

### What Happened?

Your Postman workspace has multiple collections with the same name, making it unclear which one to use.

### How to Resolve?

1. **Make Collection Name Unique**: Rename the collection in Postman to ensure it's unique.
2. **Use Collection ID**: Alternatively, provide Pynt with the **collection ID** instead of the name. The collection ID can be found in the collection properties in Postman UI.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Empty Collection Identifier Error

Fix empty collection identifier issues in Pynt. Learn how to troubleshoot and resolve problems related to missing or unrecognized collection identifiers.

{% hint style="danger" %}
**At a Glance**: 🚫 An "Empty Collection Identifier" error in Pynt indicates that a collection is missing its identifier, preventing proper recognition during testing. Follow this guide to ensure collections are correctly identified for API security scans.
{% endhint %}

***

## Error: The collection identifier provided in the Pynt configuration under "YOUR-COLLECTION" is malformed.

### What Happened?

Pynt was not able to detect the provided test collection ID.

### How to Resolve?

1. **Verify Collection**: Ensure the collection with the supplied name or ID exists in your workspace.
2. **Check for Whitespace**: Make sure no trailing whitespace (like carriage returns) was added to the collection name or ID.
3. **Save Changes**: Confirm that all changes were saved by clicking the **"Save"** button in the Postman UI.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Unreachable Target Error

Troubleshoot unreachable target issues in Pynt. Learn how to identify and fix problems preventing Pynt from accessing your API targets.

{% hint style="danger" %}
**At a Glance**: 🌐 If Pynt reports an unreachable API endpoint, it means the specified target is not accessible. Follow this guide to resolve the issue and ensure your API endpoints are reachable for security scans.
{% endhint %}

***

## Error: We identified that your target is unreachable

### What Happened?

The host for the test is not reachable from Pynt’s container.

### How to Resolve?

1. **Correct Environment File**: Ensure the correct environment file is selected in the Postman UI.
2. **Server Status**: Verify that the server under testing is up and running.
3. **Postman Accessibility**: Run your functional tests in Postman to ensure the server is accessible.
4. **Localhost Usage**: If your target is deployed locally, use **localhost** instead of **127.0.0.1** in your functional tests.
5. **Check Docker Container Access**: Use the following steps to check if the server is accessible from a Docker container:

```bash
docker run -it alpine:latest /bin/sh
apk add curl
curl <SERVER_URL>
```

Replace `<SERVER_URL>` with the URL of your server.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Target Responds with Errors Error

Resolve issues when a target responds with errors in Pynt. Learn how to troubleshoot and address problems causing API targets to return errors during security scans.

{% hint style="danger" %}
**At a Glance**: ⚠️ When your API target responds with errors during functional tests, it can disrupt the testing process. Use this guide to resolve underlying issues and ensure that your API targets respond correctly for smooth scans.
{% endhint %}

***

## Error: All responses from your functional test collection run returned with errors

### What Happened?

Pynt was not able to perform its analysis as the responses from the test collection run returned with errors.

### How to Resolve?

1. **Run Functional Tests Again**: Re-run the functional tests in Postman.
2. **Verify Requests**: Ensure all requests and tests are executed correctly.
3. **Check for Errors**: Look for unexpected **authentication errors** (e.g., 401, 403 responses) or **infrastructure errors** (e.g., 502, bad gateway).

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Unresolved Target Domain Error

Fix unresolved target domain issues in Pynt. Learn how to troubleshoot and resolve problems with domain name resolution to ensure successful API security scans.

{% hint style="danger" %}
**At a Glance**: 🌐 This error in Pynt indicates that the domain name of your API target cannot be resolved, preventing the security scan from running. Use this guide to troubleshoot and resolve domain name resolution issues, ensuring your scans can be completed successfully.
{% endhint %}

***

## Error: The target domain was unresolved

### What Happened?

The host for the test is not reachable from Pynt’s container.

Pynt couldn’t resolve the test target’s domain name to an IP or otherwise couldn’t communicate with the server.

### How to Resolve?

1. **Use "localhost"** instead of IP (e.g., "127.0.0.1") for a server running locally.
2. **Select Correct Environment**: Ensure the correct environment is selected in Postman UI.
3. **Verify Domain Reachability**: Run the test collection in Postman and confirm there are no "DNS Lookup Failed" errors.
4. **Check from Docker**: Run the following commands in a terminal to check if the domain is accessible from the Docker container:

```bash
docker run -it alpine:latest /bin/sh
ping <THE TEST DOMAIN>
```

Ensure no "Name or service not known" error messages are received.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Unresolved Variable Error

Resolve unresolved variable issues in Pynt. Learn how to troubleshoot and fix problems with unrecognized or undefined variables in your API testing.

{% hint style="danger" %}
**At a Glance**: ⚠️ An "Unresolved Variable" error in Pynt occurs when a variable in your API testing is undefined or not recognized. This guide helps you resolve unresolved variable issues, ensuring smooth and accurate API tests.
{% endhint %}

***

## Error: The functional tests had an unresolved variable

### What Happened?

Pynt was not able to run the test collections they had an unresolved variable/s.

### How to Resolve?

1. **Select Correct Environment**: Ensure the correct environment file is selected in the Postman UI.
2. **Resolve Variables**: Verify that all variables in the test collection are correctly defined and resolved.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot TLS Handshake Fail Error

Fix TLS handshake failures in Pynt. Learn how to troubleshoot and resolve issues preventing successful TLS connections during API security scans.

{% hint style="danger" %}
**At a Glance**: 🔒 TLS handshake failures in Pynt indicate that a secure connection to your API target couldn’t be established. This guide will help you resolve these issues for secure API scans.
{% endhint %}

***

## TLS Error Messages

* **TLS handshake failed because of an unauthorized certificate.**
* **TLS handshake failed because your target uses a self-signed certificate.**

### What Happened?

The SSL certificate used to identify the site is not trusted. This may be due to a self-signed certificate, an untrusted CA, or an SSL stripping mechanism.

### How to Resolve?

1. Use the `--insecure` flag when running Pynt’s Docker container:

```bash
docker run --insecure ...
```

{% hint style="warning" %}
⚠️ **Note**: Running in insecure mode means the server’s identity cannot be verified. Use this option with caution.
{% endhint %}

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Few Requests Error

Resolve few requests errors in Pynt. Learn how to troubleshoot and fix issues related to insufficient API requests as an input to the security scans.

{% hint style="danger" %}
**At a Glance**: 🛠️ A "Few Requests Error" in Pynt occurs when there are not enough API requests to perform a comprehensive security scan. This guide helps resolve the issue, ensuring sufficient data for accurate security assessments.
{% endhint %}

***

## Error: We identified only X requests. Adding more requests will provide better security test coverage

### What Happened?

Only a few requests were provided as part of the collection, which might limit the coverage of the security tests.

### How to Resolve?

1. **Add More Requests**: Increase the number of requests by adding more API endpoints or more test cases for existing endpoints.
2. **Broaden Test Coverage**: Ensure that your functional tests cover as many API requests and scenarios as possible.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot One User Only Error

Fix one user only errors in Pynt. Learn how to troubleshoot and resolve issues related to single-user testing limitations during API security scans.

{% hint style="danger" %}
**At a Glance**: 👤 This error in Pynt indicates that only one user is interacting with the API during testing, limiting the scope of the security assessment. Follow this guide to involve more users for a more comprehensive API security scan.
{% endhint %}

***

## Error: The functional tests included only one user

### What Happened?

Only a single user was provided as part of the collection, which might limit the coverage of the security tests in terms of the ability to perform business logic tests.

### How to Resolve?

1. **Add More Users**: Include additional users in the test, preferably with varying privileges (e.g., admin and regular users).
2. **Business Logic Testing**: More users allow Pynt to conduct better business logic-related security tests, providing a more thorough assessment.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# Troubleshoot Failed Assertions Error

Resolve failed assertions errors in Pynt. Learn how to troubleshoot and address issues causing your API tests to fail during security scans.

{% hint style="danger" %}
**At a Glance**: ❌ This error in Pynt occurs when your API tests do not meet the expected conditions or outcomes, leading to failed assertions. This guide helps resolve failed assertions, improving the accuracy and reliability of your security scans.
{% endhint %}

***

## Error: The functional tests had assertions that failed, which affected the security tests.

### What Happened?

Pynt has encountered assertions while running the provided functional tests, which might effect the coverage of the security tests.

### How to Resolve?

1. **Run Functional Tests**: Run your functional tests through Postman.
2. &#x20;**Fix Assertion Errors**: Identify and fix all assertion errors in your tests before running Pynt’s security scans.

***

{% hint style="info" %}
For additional support, visit [Pynt Community Support](https://www.pynt.io/community).
{% endhint %}


# How To

{% content-ref url="/pages/kcSck8NhzWyyXQslQGqp" %}
[How to Run Business Logic Tests with Pynt](/documentation/api-security-testing/how-to/how-to-run-business-logic-tests-with-pynt)
{% endcontent-ref %}

{% content-ref url="/pages/v43G6XVlGU8ZP516EJLN" %}
[How to associate a Pynt scan to an Application in Pynt Dashboard](/documentation/api-security-testing/how-to/how-to-associate-a-pynt-scan-to-an-application-in-pynt-dashboard)
{% endcontent-ref %}

{% content-ref url="/pages/JGNrXPWdcuJRFRCSzUTW" %}
[How to tag a scan in Pynt](/documentation/api-security-testing/how-to/how-to-tag-a-scan-in-pynt)
{% endcontent-ref %}


# How to Run Business Logic Tests with Pynt

## How to Run Business Logic Tests with Pynt

Business logic tests are essential for identifying vulnerabilities like those in the OWASP API Top 10. Pynt simplifies this process but may require specific inputs to test certain vulnerabilities. This guide explains how to provide the necessary input and run business logic tests effectively.

### Understanding Input Requirements

If your scan results indicate that vulnerabilities like OWASP 2023:API1 or OWASP 2023:API5 were not tested due to a lack of input, it often means that Pynt needs API traffic from at least two different authenticated users. This diversity in traffic enables Pynt to analyze multi-user interactions, which are critical for detecting certain vulnerabilities.

> #### About OWASP 2023:API1 - Broken Object Level Authorization
>
> This vulnerability occurs when an API improperly verifies if a user is authorized to access a particular object. Attackers can exploit this by manipulating object identifiers to access data they shouldn’t have access to, such as another user’s personal information or sensitive business data.
>
> Testing for this vulnerability requires multiple authenticated users to demonstrate whether proper object-level authorization checks are in place.

> #### About OWASP 2023:API5 - Broken Function Level Authorization
>
> This vulnerability arises when APIs fail to enforce function-level restrictions properly. Users with lower privileges may exploit this to execute unauthorized actions by invoking high-privilege API endpoints.
>
> To test for this, Pynt requires requests from users with different privilege levels to evaluate whether function-level authorization is enforced consistently.

### Providing Input for Business Logic Tests

#### Example 1: Using Postman Collections with Requests from Two Users

<figure><img src="/files/9e16goVmCZffHrR9ifra" alt=""><figcaption></figcaption></figure>

1. Create a Postman collection containing requests from two authenticated users.
   * For example, in the `Goat` example application, include login and activity requests from `User A` and `User B` in the same collection.
2. Run the scan using the Postman collection with Pynt.

   ```bash
   pynt newman --collection collection.json
   ```

#### Example 2: Using Postman Environments for Multiple Users

1. Create two Postman environment files, each containing the credentials of one authenticated user:
   * `env1.json` for `User A`
   * `env2.json` for `User B`
2. Run Pynt with both environment files:

   ```bash
   pynt newman --collection collection.json --environment env1.json env2.json
   ```

   In this setup:

   * Pynt runs the collection twice, once per user.
   * This provides the required multi-user traffic for testing.

#### Example 3: Using Browser with Pynt Listen

<figure><img src="/files/Cigf7kaQQYSnT3plyX14" alt=""><figcaption><p>Testing crAPI for business Logic issues with two browser windows</p></figcaption></figure>

1. Start Pynt in listen mode to capture API traffic:

   ```bash
   pynt listen --captured-domains <domain>
   ```
2. Open a browser and log in to the tested web application using two different users:
   * Open two separate browser tabs or windows.
   * Log in as `User A` in one tab.
   * Log in as `User B` in the other tab.
3. Perform relevant actions for both users to generate API traffic.
4. Stop Pynt after capturing the traffic by pressing `Enter` in the terminal.
5. Run the scan with the captured traffic.

### Checking Captured Users in the Traffic

<figure><img src="/files/RxC3ZHWCwYCoISxxas8M" alt=""><figcaption></figcaption></figure>

To see how many users Pynt captured in the API traffic:

1. Open the Pynt HTML report generated after the scan.
2. Navigate to the **Functional Tests By Endpoints** section at the end of the report.
3. Review the **number of users** discovered for each endpoint in the traffic.

This information helps verify if sufficient multi-user traffic was captured for comprehensive testing.

### Verification

After running the business logic tests:

* Verify that vulnerabilities like OWASP 2023:API1 and OWASP 2023:API5 are now tested.

By ensuring diverse, authenticated traffic, Pynt can effectively test for business logic vulnerabilities. Let me know if you need further clarification or additional examples!


# How to associate a Pynt scan to an Application in Pynt Dashboard

## How to Associate a Pynt Scan to an Application in the Pynt Dashboard

To ensure your Pynt scans are linked to the appropriate application in the Pynt Dashboard, follow the steps outlined below. Proper association ensures better organization and relevance of the findings.

### Using the Pynt CLI

1. **Locate the Application ID**:
   * Navigate to the `Applications` page in the Pynt Dashboard.
   * Find the desired application and note its `Application ID`.
2. **Run the Pynt Scan with** `--application-id`:

   * Include the `--application-id` flag in your Pynt CLI command.
   * Replace `<application-id>` with the actual ID obtained from the dashboard.

   **Example Command**:

   ```bash
   pynt [COMMAND] [OPTIONS] --application-id <application-id>
   ```

   **Parameters**:

   * `[COMMAND]`: The specific Pynt integration you wish to run.
   * `[OPTIONS]`: Any additional options required for the command.
   * `<application-id>`: The ID of the application to associate the scan with.

### Configuring Postman Integration

If you are using Postman integration with Pynt, you need to set the application ID in the Pynt Postman collection variables.

1. **Open the Pynt Postman Collection**:
   * Download and import the Pynt Postman collection from the Pynt Postman workspace.
2. **Set the Application ID**:

   * Open the `Variables` section of the collection.
   * Locate the `PYNT-ENTERPRISE-APP-ID` variable.
   * Replace its value with the `Application ID` of the target application from the Pynt Dashboard.

   <figure><img src="/files/c9ltCWu9SIOM10xP07RO" alt=""><figcaption></figcaption></figure>
3. **Save the Changes**:
   * Save the updated collection.
   * Proceed with the Postman workflows, ensuring scans are properly associated.

### Verification

<figure><img src="/files/dI6ChMhvZXczuFgZrlQz" alt=""><figcaption></figcaption></figure>

After running the scan:

* Navigate to the `Applications` page in the Pynt Dashboard.
* Open the target application.
* Verify that the scan results appear under the correct application.

By following these steps, you can ensure that your Pynt scans are correctly associated with the desired applications in the Pynt Dashboard, both through the CLI and Postman integration.


# How to tag a scan in Pynt

Adding tags to your Pynt scans allows for better organization and traceability. These tags are visible in the Pynt Dashboard and can help identify scans based on context, such as the current Git commit or branch.

### Using the Pynt CLI to Add Tags

To tag a scan, use the `--tag` option with your Pynt CLI command. You can add multiple tags by repeating the `--tag` option.

#### Example 1: Add the Current Git Short Hash as a Tag

You can include the current Git commit hash as a tag to track the scan's association with a specific code state.

```bash
pynt [COMMAND] [OPTIONS] --tag $(git rev-parse --short HEAD)
```

In this example:

* `$(git rev-parse --short HEAD)` dynamically retrieves the short hash of the current Git commit.
* The hash is added as a tag to the scan.

#### Example 2: Add the Git Branch Name as a Tag

Similarly, you can tag a scan with the name of the current Git branch to reflect the source branch of the code.

```bash
pynt [COMMAND] [OPTIONS] --tag $(git rev-parse --abbrev-ref HEAD)
```

In this example:

* `$(git rev-parse --abbrev-ref HEAD)` retrieves the name of the current branch.
* The branch name is added as a tag to the scan.

#### General Syntax

```bash
pynt [COMMAND] [OPTIONS] --tag <tag> --tag <another-tag>
```

* `[COMMAND]`: The specific Pynt command you wish to execute.
* `[OPTIONS]`: Additional options for the command.
* `<tag>`: The tag you wish to add. Replace with a meaningful label or value.

You can add multiple tags by including the `--tag` option multiple times. All tags will be displayed in the Pynt Dashboard.

### Viewing Tags in the Pynt Dashboard

After running a scan with tags:

<figure><img src="/files/1cNfKLv0jIXLjt2vvRb0" alt=""><figcaption></figcaption></figure>

1. Go to the `Scans History` section in the Pynt Dashboard.
2. Locate the relevant scan in the scan history.
3. Tags will be displayed alongside the scan details.

Additionally, you can view the tags in the `Last Scan` area of the application page.

Using tags effectively can greatly enhance your ability to organize and track scans in Pynt.


# Benchmarks


# Pynt vs OWASP crAPI

[OWASP **crAPI**](https://github.com/OWASP/crAPI) (Completely Ridiculous API) is an intentionally vulnerable API designed to help security professionals and developers learn about API security risks. It simulates real-world API security flaws, including:

* **Broken Object Level Authorization (BOLA)**
* **Broken User Authentication**
* **Excessive Data Exposure**
* **Security Misconfigurations**
* **Injection Attacks**

crAPI provides a hands-on environment for practicing API security testing, exploiting vulnerabilities, and learning how to secure APIs effectively. It's useful for penetration testers, security engineers, and developers looking to improve their API security skills.

## crAPI Security Challenges

Pynt uncovers the underlying vulnerabilities in crAPI (such as BOLA, mass assignment, SQL/NoSQL injection, etc.), rather than demonstrating the full exploits themselves. The goal is to identify where the API is weak and prove that those weaknesses can be triggered, without carrying out the destructive or business-logic-breaking steps of the exploit. This way, Pynt provides actionable findings while keeping testing safe and controlled.

<table data-full-width="true"><thead><tr><th width="47.703125">#</th><th width="361.8671875">Category</th><th>Challenge</th><th>Pynt Coverage</th><th>How to run ?</th></tr></thead><tbody><tr><td>1</td><td>BOLA (Broken Object-Level Authorization)</td><td>Access details of another user’s vehicle</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - User data leakage to other users - Resource-ID authorization</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr><tr><td>2</td><td>BOLA (Broken Object-Level Authorization)</td><td>Access mechanic reports of other users</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - User data leakage to other users - Resource-ID authorization</td><td><a href="#how-to-scan-crapi-with-pynt-using-pynt-modified-postman-collection">crAPI modified postman collection</a></td></tr><tr><td>3</td><td>Broken Authentication</td><td>Reset the password of a different user</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - Rate-limit enforcement for OTP Endpoints</td><td><a href="#how-to-scan-crapi-with-pynt-using-pynt-modified-postman-collection">crAPI modified postman collection</a></td></tr><tr><td>4</td><td>Excessive Data Exposure</td><td>Find an API endpoint that leaks sensitive information of other users</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - Excessive Data Exposure</td><td><a href="#how-to-scan-crapi-with-pynt-using-pynt-modified-postman-collection">crAPI modified postman collection</a></td></tr><tr><td>5</td><td>Excessive Data Exposure</td><td>Find an API endpoint that leaks an internal property of a video</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - Mass assignment by manipulation of hidden attributes</td><td><a href="#how-to-scan-crapi-with-pynt-using-pynt-modified-postman-collection">crAPI modified postman collection</a></td></tr><tr><td>6</td><td>Rate Limiting / DoS</td><td>Abuse the “contact mechanic” feature for a denial-of-service attack</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - Multiple Requests Rate Limit (Need to enable in Pynt dashboard. Application -> tests -> include in scans)</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr><tr><td>7</td><td>BFLA (Broken Function-Level Authorization)</td><td>Delete a video of another user</td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span> - Will be supported in the upcoming update to the Business logic package </td><td></td></tr><tr><td>8</td><td>Mass Assignment</td><td>Get an item for free</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - Negative Value Injection</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr><tr><td>9</td><td>Mass Assignment</td><td>Increase your balance by $1,000 or more</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - Negative Value Injection</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr><tr><td>10</td><td>Mass Assignment</td><td>Update internal video properties</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - Mass assignment by manipulation of hidden attributes</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr><tr><td>11</td><td>SSRF (Server-Side Request Forgery)</td><td>Make crAPI send an HTTP call to “www.google.com” and return the response</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - Remote resource access</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr><tr><td>12</td><td>NoSQL Injection</td><td>Get free coupons without knowing the coupon code</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - NoSQL Injection</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr><tr><td>13</td><td>SQL Injection</td><td>Redeem a coupon that has already been claimed</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - PostgreSQL Injection</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr><tr><td>14</td><td>Unauthenticated Access</td><td>Find an endpoint that does not perform authentication checks</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - Ignored authentication token</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr><tr><td>15</td><td>JWT Vulnerabilities</td><td>Forge valid JWT tokens</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - JWT Forgery via External JWKS</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr><tr><td>S1</td><td>Secret Challenge</td><td>Undisclosed (advanced hidden challenge)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> - Negative Value Injection</td><td><a href="#how-to-scan-crapi-with-pynt-using-the-crapi-postman-collection">crAPI official postman collection</a></td></tr></tbody></table>

<h2 align="center">Other Notable findings by Pynt</h2>

<table data-full-width="true"><thead><tr><th width="340.7578125">Vulnerability </th><th width="446.8828125">Endpoint</th><th>explanation</th></tr></thead><tbody><tr><td>User data leakage to other users - credentials authorization</td><td>POST /identity/api/v2/user/change-email</td><td>User can initiate email change for a different user, the verify will not work so the impact is Low</td></tr><tr><td>User data manipulation by other users - Resource-ID authorization</td><td>POST /workshop/api/merchant/contact_mechanic.</td><td>User can initiate a mechanic call for a different User, impact is low</td></tr><tr><td>Exposed .env File</td><td>/.env</td><td><p></p><p>Pynt detected an exposed environment file located in the server root</p></td></tr></tbody></table>

## How to get crAPI ?&#x20;

First we will need to setup crAPI as described here: <https://github.com/OWASP/crAPI>

Or just use prebuilt images:

#### Linux machines:

```bash
curl -o docker-compose.yml https://raw.githubusercontent.com/OWASP/crAPI/main/deploy/docker/docker-compose.yml

docker-compose pull

docker-compose -f docker-compose.yml --compatibility up -d
```

#### Windows machines:

```bash
curl.exe -o docker-compose.yml https://raw.githubusercontent.com/OWASP/crAPI/main/deploy/docker/docker-compose.yml

docker-compose pull

docker-compose -f docker-compose.yml --compatibility up -d
```

## How to scan crAPI with Pynt using the crAPI postman collection ?

#### Get the official crAPI postman collection and environment files:

<pre data-full-width="false"><code><strong>wget https://raw.githubusercontent.com/OWASP/crAPI/refs/heads/main/postman_collections/crAPI.postman_collection.json
</strong>wget https://raw.githubusercontent.com/OWASP/crAPI/refs/heads/main/postman_collections/crAPI.postman_environment.json
wget -O crAPI.postman_environment2.json https://raw.githubusercontent.com/OWASP/crAPI/refs/heads/main/postman_collections/crAPI.postman_environment.json
</code></pre>

The second environment file will make Pynt run the collection twice, simulating traffic for two users. This enables Pynt to perform Business Logic Attacks.

{% hint style="danger" %}
On Mac and Windows PCs modify the base URLs in the environment files to be `localhost` and not `127.0.0.1`&#x20;

```
"values": [{
        "key": "url",
        "value": "http://localhost:8888",
        "enabled": true
    },
    {
        "key": "url_mail",
        "value": "http://localhost:8025",
        "enabled": true
    }
],
```

{% endhint %}

### Install Pynt CLI

`python3 -m pip install pyntcli`

Run Pynt with crAPI postman collection:

{% code overflow="wrap" fullWidth="false" %}

```bash
pynt newman --collection crAPI.postman_collection.json --environment crAPI.postman_environment.json crAPI.postman_environment2.json
```

{% endcode %}

## How to scan crAPI with Pynt using Pynt modified postman collection ?

To get some challenges we created two new postman collections:

&#x20;[**crAPI-modified.json**](https://raw.githubusercontent.com/pynt-io/pynt/refs/heads/crapi-cloud-files/crapi/crAPI-modified-v2.1.json) - A collection that includes APIs that where missing from the original collection.

{% code overflow="wrap" %}

```bash
wget https://raw.githubusercontent.com/pynt-io/pynt/refs/heads/crapi-cloud-files/crapi/crAPI-modified-v2.1.json
```

{% endcode %}

[**crAPI-alignment\_collection-v2.json**](https://raw.githubusercontent.com/pynt-io/pynt/refs/heads/main/crapi/crAPI-alignment_collection-v3.json) - Populates lot more user data into crAPI database, helps with finding some of the challenges

1. First run the alignment collection against crAPI:

```bash
newman run crAPI-alignment_collection-v2.json -e crAPI.postman_environment.json
```

2. Now run the Pynt scan:

{% code overflow="wrap" %}

```bash
pynt newman --collection crAPI-modified.json --environment crAPI.postman_environment.json crAPI.postman_environment2.json
```

{% endcode %}


# Pynt vs VAmPI

VAmPI (The Vulnerable API) is an intentionally vulnerable API designed to help security professionals and developers learn about API security risks. It simulates real-world API security flaws, including:

* **Broken Object Level Authorization (BOLA)**
* **Broken User Authentication**
* **Excessive Data Exposure**
* **Security Misconfigurations**
* **Injection Attacks**

VAmPI provides a hands-on environment for practicing API security testing, exploiting vulnerabilities, and learning how to secure APIs effectively. It's useful for penetration testers, security engineers, and developers looking to improve their API security skills.

### How to scan VAmPI with Pynt ?

#### Step 1: Install VAmPI

First we will need to setup VAmPI as described here: <https://github.com/erev0s/VAmPI>

Or just use prebuilt docker images:

```bash
docker run -p 5000:5000 erev0s/vampi:latest
```

#### Step 2: Download the below Postman collections&#x20;

{% file src="/files/3itrrN0EPJLA1K6JJVQB" %}

{% file src="/files/HwUaYUmmB4NlF7CvKX5Z" %}

#### Step 3: Run the setup collection

The setup postman collection will initialize VAmPI's database and add some users to it

**Option 1:** Import the "vampi setup.postman\_collection.json" to your postman workspace and run it

**Option 2**: Use postman's CLI "newman" &#x20;

```
newman run "vampi setup.postman_collection.json"
```

#### Step 4: Install Pynt CLI

If you don't have Pynt's CLI installed, install it using:

Linux:

`python3 -m pip install pyntcli`

Windows:

`python -m pip install pyntcli`

#### Step 5: Run the scan

Run Pynt with VAmPI postman collection:

{% code fullWidth="false" %}

```bash
pynt newman --collection VAmPI_Test.postman_collection.json 
```

{% endcode %}

### **FAQ**&#x20;

**Q: Why am I not seeing the same results when using the official VAmPI collection?**&#x20;

**A:** Deliberately vulnerable applications like VAmPI can sometimes be *too* broken to accurately represent real-world scenarios. For example, the official VAmPI collection sends unauthenticated requests to sensitive endpoints, such as debug and user details. Since these endpoints respond without authentication, Pynt’s analysis engine assumes the data is intentionally public and skips authorization testing (e.g., BOLA) for them.

This behavior is by design to avoid false positives on endpoints that appear to be publicly accessible.


# Pynt with API Testing Tools

Enhance your API security testing with Pynt's seamless integration into popular API testing tools like Postman, ReadyAPI, and Insomnia. Secure your APIs effortlessly within your favorite tools.

## Pynt Integration with API Testing Tools

{% hint style="success" %}
🔧 **Seamless Integration**: Pynt integrates directly with leading API testing tools like **Postman**, **ReadyAPI**, and **Insomnia**, allowing developers and testers to enhance API security testing without switching platforms.
{% endhint %}

***

## Advantages for Developers and Testers

By embedding security into existing testing tools, **developers and testers** can easily integrate API security checks into their regular workflows. There’s no need to learn new tools or disrupt existing processes. Pynt’s automation ensures security scans are performed alongside functional tests, catching vulnerabilities early and minimizing delays.

***

{% hint style="warning" %}
🚨 **Pain Point**: Developers and testers are not security experts and typically won’t use standalone security tools. By embedding security testing directly into their familiar tools, Pynt ensures that security becomes part of their daily workflow without needing additional expertise.
{% endhint %}

***

## Benefits for AppSec Teams

For **AppSec teams**, Pynt’s integration with testing tools offloads much of the manual security work, allowing them to focus on managing the security program rather than conducting complex API security tests.

{% hint style="info" %}
💼 **AppSec Focus**: AppSec teams can focus on overseeing and managing the security program, while Pynt automates the heavy lifting of running complex API security tests, ensuring continuous protection without requiring direct involvement.
{% endhint %}

***

For more details on how Pynt integrates with specific tools, visit:

* [Pynt with Postman](/documentation/security-testing-integrations/pynt-with-api-testing-tools/pynt-for-postman)
* [Pynt with ReadyAPI](/documentation/security-testing-integrations/pynt-with-api-testing-tools/pynt-for-readyapi)
* [Pynt with Insomnia](/documentation/security-testing-integrations/pynt-with-api-testing-tools/pynt-for-insomnia)


# Pynt for Postman

Run API security testing from Postman desktop application.

{% hint style="success" %}
**NEW**! for **Postman's team users**. Pynt is now natively integrated within the Postman UI - download the full onboarding instructions below. If you're not a Postman team user, you can still use Pynt in the older way -  refer to the instructions on this page.&#x20;
{% endhint %}

{% file src="/files/rmFDtGibOmZgj1yU3KAD" %}
Pynt for Postman Team Users - Customer Onboarding Guide
{% endfile %}

## What is Postman?

{% hint style="info" %}
💡 [**Postman** ](https://www.postman.com/)is a powerful API development tool that simplifies the design, testing, and documentation of APIs. With its intuitive interface, developers can easily create HTTP requests, inspect responses, and automate workflows, making it essential for API testing.
{% endhint %}

<figure><img src="/files/SqZaTruetF9wjIGxa1Sw" alt="" width="124"><figcaption><p>Postman</p></figcaption></figure>

***

## Pynt's Integration with Postman&#x20;

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview) suit, Pynt allows seamless integration with Postman.

Pynt helps you analyze API traffic, run security tests, and identify risks early in the development process - all within Postman. The integration is seamless, making security testing a natural extension of your API testing process.

{% hint style="success" %}
🔒 **Pynt + Postman**: Integrating Pynt with Postman allows you to automatically generate **context-aware security tests** from your existing Postman collections. Enhance your security without disrupting your workflow.
{% endhint %}

{% hint style="info" %}
🚀 **Most Popular**: Pynt is the most popular application security tool on the [Postman API Network](https://www.postman.com/category/app-security), making it a top choice for developers and testers looking to embed security into their API testing!
{% endhint %}

***

## Start Running Pynt with Postman

There are two quick ways to start running Pynt with Postman:

***

### Local Scan

Running Pynt locally within Postman (requires installing Pynt's container) using Pynt's Postman wizard. This option is free and available as part of Pynt's free starter plan. Use this option if you can't access your APIs from the cloud or prefer the integrated experience. It's free under Pynt's [Starter Plan](https://www.pynt.io/pricing) and ideal if your APIs aren’t accessible from the cloud or if you prefer an integrated local experience.

Start now from [here](https://app.pynt.io/onboard/postman/login).

***

### Cloud Scan

Integrating Pynt with Postman and running it from Pynt SaaS platform. This option is available via Pynt’s business plan under a free trial. Use this option if you prefer not to install Pynt's container and have public access to your APIs. It's available under Pynt’s [Business Plan](https://www.pynt.io/pricing) with a free trial. Ideal for cloud setups with easier configuration.

Start now from [here](https://app.pynt.io).

***

### How to Choose

{% hint style="info" %}
💡 **Local Scan**: Choose this if you prefer to run Pynt directly from Postman with a local setup (requires installing Pynt's container).
{% endhint %}

{% hint style="info" %}
💡 **Cloud Scan**: Choose this if you want to run Pynt from the SaaS platform (no container needed) with public API access.
{% endhint %}

***

## Pynt for Postman Tutorial Video

Our **Pynt for Postman** tutorial video walks you through the process of integrating Pynt with Postman for effective API security testing. In this video, you'll learn how to set up Pynt within your Postman environment, run security scans, and analyze the results to ensure your APIs are protected from vulnerabilities.

Whether you're new to Pynt or looking to enhance your API security practices, this tutorial provides clear, step-by-step instructions to get you started.

🎥 **Watch the tutorial video now** - secure your APIs in just a few minutes: Pynt for Postman Video:

{% embed url="<https://www.youtube.com/watch?v=lkQam7zeZD0>" %}
Pynt for Postman Video
{% endembed %}

***

{% hint style="warning" %}
🚨 **Stay Secure**: With Pynt for Postman, you can ensure your APIs are protected from emerging threats, all within the familiar Postman interface.
{% endhint %}


# Fork Pynt Collection

Effortlessly integrate Pynt with Postman! Follow our onboarding guide to learn how to fork Pynt's Postman collection, enabling you to harness advanced API security features seamlessly.

{% hint style="success" %}
🚀 **Quick Start**: The fastest way to begin running Pynt from Postman is by using [**Pynt's Postman Wizard**](https://app.pynt.io/onboard/postman/login). It simplifies the process and gets you started in just a few steps! This will allow you to skip the manual steps below.
{% endhint %}

***

## Fork Pynt Collection from Pynt Public Workspace

If you prefer to run Pynt locally and wish to manually setup the integration, **fork the Pynt collection** from Postman's public API network.

1. Go to the [**Pynt public workspace**](https://www.postman.com/pynt-io/pynt/overview).
2. Fork the 'Pynt' collection to your workspace.
3. Optionally, fork the 'goat' collection for a reference app.
4. Open your workspace in the Postman desktop app.
5. Click on **Pynt’s collection documentation** and follow the instructions.

<figure><img src="https://content.pstmn.io/a93329de-85be-434a-a6d5-cba3585d984c/R3JvdXAgMjM3NTk0LnBuZw==" alt=""><figcaption><p>Image 1 - Fork Pynt collection into your workspace</p></figcaption></figure>

<figure><img src="https://content.pstmn.io/42465f77-1503-484f-88d4-217534ae8b82/SW1hZ2UtMi5wbmc=" alt=""><figcaption><p>Image 2 - Open Pynt collection from your workspace in Postman app</p></figcaption></figure>

<figure><img src="https://content.pstmn.io/662255dc-06b3-475f-bcbc-13d1b0dfa92d/aW1hZ2UtMy5wbmc=" alt=""><figcaption><p>Image 3 - Continue with Pynt's collection documentation</p></figcaption></figure>

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Run Pynt Container

Learn why running the Pynt container is crucial for local tests and how the Postman CLI facilitates communication for seamless security scans.

{% hint style="info" %}
💡 **Running Pynt Container**: The Pynt container is needed to perform API security tests locally. It acts as the engine that executes the security scans, processing API traffic in real-time and applying context-aware tests to detect vulnerabilities.
{% endhint %}

***

## Setup

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).

***

## Running Pynt CLI Command for Postman&#x20;

{% hint style="info" %}
💡 **Postman CLI Command**: Running Pynt for Postman CLI command is required to allow **Pynt's container** to communicate with the Postman application. This ensures that security tests generated by Pynt can be executed efficiently within the Postman environment.
{% endhint %}

### Basic usage

```bash
pynt postman
```

### Optional arguments

{% code overflow="wrap" fullWidth="false" %}

```bash
    --port - set the port pynt will listen to (DEFAULT: 5001)
    --insecure - use when target uses self signed certificates
    --host-ca - path to the CA file in PEM format to enable SSL certificate verification for pynt when running through a VPN.
```

{% endcode %}

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Run Pynt in Postman

Run Pynt's Postman collection effortlessly! Explore our onboarding guide to learn how to execute the Pynt collection within Postman, ensuring a smooth integration of Pynt's API security features with

{% hint style="success" %}
🚀 **Quick Start**: The easiest way to begin running Pynt in Postman is by using the [**Pynt Postman Wizard**](https://app.pynt.io/onboard/postman/login), which guides you through the integration step-by-step.
{% endhint %}

Running the Pynt collection in Postman is a straightforward process that allows you to perform comprehensive API security testing. This guide will walk you through the steps to execute a Pynt collection, helping you identify vulnerabilities and assess the security posture of your APIs.

***

## Configure Pynt Collection

{% hint style="info" %}
💡 **Postman API Key and Collection Setup**: Configuring the Pynt collection with the **Postman API key** and the reference **collection name/ID** is necessary for Pynt to access your Postman workspace and generate security tests. The API key grants permission for Pynt to interact with your collections, and the collection name/ID ensures that Pynt applies the security tests to the correct API set.
{% endhint %}

**Fill in the required parameters in Pynt's collection:**

* **API-KEY**: Enter your Postman API key under the 'Current Value' column. Generate a key if necessary at [Postman API Keys](https://postman.co/settings/me/api-keys).
* **port**: The port number used in the Docker run command (default: 5001).
* **YOUR-COLLECTION**: The functional test collection name or UID (UID is preferred).
* **scanId**: Output variable (ignore).

{% hint style="info" %}
💡 **Reference App**: Pynt provides a vulnerable app example called 'goat', which you can fork from the [**Pynt public workspace**](https://www.postman.com/pynt-io/workspace/pynt) for testing purposes.
{% endhint %}

***

## Running the Collection

* After filling in the parameters, click **'Save'**.
* If you modify your test collection, re-run the Pynt collection.
* To test another collection, update the **YOUR-COLLECTION** variable and re-run the Pynt collection.

{% hint style="warning" %}
⚠️ **Tip**: Ensure you use the correct API key and accurate collection name or ID to avoid issues while running the collection.
{% endhint %}

***

<figure><img src="/files/GR5aPc5fwqTnKub0O5lD" alt=""><figcaption><p>Image 1 - Generate / Copy API Key if forgotten</p></figcaption></figure>

<figure><img src="/files/wgmGxLCXlkl4UXow6Qgs" alt=""><figcaption><p>Image 2 - Enter 'Pynt' collection parameters</p></figcaption></figure>

<figure><img src="/files/lDVG1geU3EUOPdBdueEy" alt=""><figcaption><p>Image 3 - Run the 'Pynt' collection to generate full OWASP-10 API-security tests for your collection</p></figcaption></figure>

***

{% hint style="info" %}
💡 **Pynt for Postman Troubleshooting**: For problems with Pynt’s Postman integration, check the [**Pynt for Postman Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-for-postman-troubleshooting) for step-by-step troubleshooting assistance.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# View Scan Results in Postman

Analyze your results with ease! Explore our onboarding guide to learn how to view the results of Pynt's Postman collection. Gain valuable insights into your API security testing.

## Pynt Scan Report

Pynt scan report provides detailed insights into the security of your APIs. This guide will help you access and analyze scan results, enabling you to identify vulnerabilities, assess risk levels, and take action to secure your APIs. Understanding scan results is essential for maintaining strong API security.

***

## Accessing Scan Results

{% hint style="success" %}
📊 **Quick View**: Pynt will automatically open the scan report in your browser once the scan completes. If you prefer, you can always view the report within Postman by following the instructions below.
{% endhint %}

1. **OWASP-10 Results**: The security results categorized by OWASP-10 will appear on the main console screen.
2. **View Summary**: Click on 'View Summary' to access a high-level overview of the results.
3. **Full Report**: To view the full report:
   * Uncollapse the 'Pynt' collection.
   * Go to the last request, 'Show Report'.
   * Click on 'Send' and select the 'Visualize' tab in the lower section to view the full report.

***

<figure><img src="/files/teF89m8ysYIuh9CZwi35" alt=""><figcaption><p>Image 1 - View the API security test results</p></figcaption></figure>

<figure><img src="/files/MK0MQNhUnkBnxl3qhsCZ" alt=""><figcaption><p>Image 2 - View results summary</p></figcaption></figure>

<figure><img src="/files/VXhKQLXdxyS5Va6o3gmL" alt=""><figcaption><p>Image 3 - View visualize report</p></figcaption></figure>

***

{% hint style="info" %}
💡 **Pynt for Postman Troubleshooting**: For problems with Pynt’s Postman integration, check the [**Pynt for Postman Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-for-postman-troubleshooting) for step-by-step troubleshooting assistance.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for Insomnia

Run Pynt API security tests from Insomnia API testing application

## **What is Insomnia?**

{% hint style="info" %}
💡 [**Insomnia**](https://insomnia.rest/) by Kong is a powerful API client and design tool known for its sleek, intuitive interface. It supports REST, GraphQL, and WebSockets, and offers features like environment variables, authentication helpers, and code generation to streamline API development.
{% endhint %}

<figure><img src="/files/0vssJW6nMIPAXyFb3CXS" alt=""><figcaption><p>Insomnia</p></figcaption></figure>

***

## Pynt's Integration with Insomnia

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview) suit, Pynt allows seamless integration with any Insomnia tests.

By integrating Pynt with Insomnia, you can leverage the power of this vast platform while enhancing your API security. Pynt automatically generates context-aware security tests based on your Insomnia  tests, enabling you to identify vulnerabilities early in the development cycle and reduce the risk of security issues in production.

***

## Quick start&#x20;

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).
3. Download [`insomnia_goat.json`](https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/Insomnia_goat.json) functional test and import it into Insomnia.

In this example, we will use [`pynt listen`](/documentation/api-security-testing/pynt-cli-modes/pynt-listen-cli-mode) and set it to capture all domains (no filter)

```bash
pynt listen --captured-domains "*"
```

***

## Configuring Insomnia to use Pynt as a proxy

1. Open Insomnia.
2. Navigate to the settings by clicking on "Preferences" or use the shortcut `Ctrl+,` (`Cmd+,` on macOS).
3. In the Preferences window, go to the "Proxy" tab.
4. Check the option "Enable HTTP Proxy".
5. Set the "HTTP Proxy" field to `127.0.0.1` and the "Port" to `6666`, which matches the Pynt listening address and port.
6. If you're working with HTTPS requests, also check "Enable HTTPS Proxy" and use the same proxy settings.
7. Close the Preferences window and proceed with your API requests as usual.

We will see the following output, meaning Pynt is listening on port 6666 for incoming traffic

<figure><img src="/files/zzXtf5u2ke9GcduKE8CZ" alt=""><figcaption><p>Pynt listen mode</p></figcaption></figure>

Run the goat tests on Insomnia, All the HTTP and HTTPS requests from Insomnia will now be routed through Pynt. When done, return to the terminal and hit Enter to start Pynt scan on the traffic generated by Insomnia

<figure><img src="/files/5JnAxRjSQxPvXpj5Lfdt" alt=""><figcaption><p>Pynt for Insomnia example</p></figcaption></figure>

When the scan is complete the Pynt report will open in the browser.

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for ReadyAPI

Run Pynt API security tests from ReadyAPI testing application

## **What is ReadyAPI?**

{% hint style="info" %}
💡 [**ReadyAPI**](https://smartbear.com/product/ready-api/overview/) by SmartBear is a comprehensive API testing tool designed for functional, security, and performance testing. Known for its powerful features, ReadyAPI allows developers to automate and streamline API testing workflows. The tool supports REST, SOAP, and GraphQL, making it versatile for various API types.
{% endhint %}

<figure><img src="/files/90Vbt401HKLkKtyqVfW8" alt="" width="375"><figcaption><p>ReadyAPI</p></figcaption></figure>

***

## Pynt's Integration with ReadyAPI&#x20;

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview) suit, Pynt allows seamless integration with any ReadyAPI tests.\
By integrating Pynt with ReadyAPI, you can leverage the power of this vast platform while enhancing your API security. Pynt automatically generates context-aware security tests based on your ReadyAPI tests, enabling you to identify vulnerabilities early in the development cycle and reduce the risk of security issues in production.

***

## Quick start&#x20;

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container  [here](/documentation/api-security-testing/how-to-install-pynt-cli).

For this example, we will use [`pynt listen`](/documentation/api-security-testing/pynt-cli-modes/pynt-listen-cli-mode) and set it to capture all domains:

```bash
pynt listen --captured-domains "*"
```

We will see the following output, meaning Pynt is listening on port 6666 for incoming traffic

<figure><img src="/files/zzXtf5u2ke9GcduKE8CZ" alt=""><figcaption><p>Pynt listen mode</p></figcaption></figure>

Now on ReadyAPI, click on:

`ReadyAPI preferences -> Proxy -> Manual HTTP -> Host: 127.0.0.1, Port: 6666`

<figure><img src="/files/m5GfUYaBbV6WVBSlZyKL" alt=""><figcaption><p>ReadyAPI proxy setup</p></figcaption></figure>

Run the functional tests on ReadyAPI, when done return to the terminal and hit Enter to start Pynt scan on the traffic generated by ReadyAPI

<figure><img src="/files/5JnAxRjSQxPvXpj5Lfdt" alt=""><figcaption><p>Pynt for ReadyAPI example</p></figcaption></figure>

When scan is complete the Pynt report will open in the browser.

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt with API Testing CLIs

Pynt integrates effortlessly with API testing CLI tools, providing developers with powerful, automated security testing directly from the command line.

## Pynt CLI Integration with API Testing CLIs

Pynt integrates with API testing tools like **Postman** and **ReadyAPI** through their CLIs, enabling automated API security tests directly from the command line. This makes testing across environments and CI/CD pipelines more efficient by automating test executions.

***

## Advantages of Running Pynt via CLI

{% hint style="success" %}
🚀 **Automation and Efficiency**: Running Pynt via CLI automates security tests as part of your CI/CD pipeline, ensuring that every API change is tested for vulnerabilities, reducing the risk of security flaws reaching production.
{% endhint %}

***

{% hint style="info" %}
📈 **Scalability**: Easily scale your security testing across environments (development, staging, production). Pynt runs in parallel with existing tests, ensuring full coverage without slowing down processes.
{% endhint %}

***

{% hint style="warning" %}
⚙️ **Flexibility**: Customize test parameters, schedule scans, and integrate with various automation tools, all from the command line, giving you complete control over your security testing strategy.
{% endhint %}

***

{% hint style="info" %}
💡 **Seamless Integration**: Pynt integrates smoothly with popular API testing CLI tools, allowing you to add security testing to your workflows without extra setup or configuration.
{% endhint %}

***

## Available CLI Integrations:

* [**Newman** (Postman CLI)](/documentation/security-testing-integrations/pynt-with-api-testing-clis/pynt-for-newman-postman-cli)
* [**ReadyAPI testrunner**](/documentation/security-testing-integrations/pynt-with-api-testing-clis/pynt-for-testrunner-readyapi-cli)

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for Newman (Postman CLI)

Run Pynt API security tests on a locally stored postman collection from a terminal

## **What is Newman?**

{% hint style="info" %}
💡 [**Newman**](https://learning.postman.com/docs/collections/using-newman-cli/command-line-integration-with-newman/) is the CLI tool for running Postman collections. It enables you to automate and integrate API tests directly into your CI/CD pipelines.
{% endhint %}

<figure><img src="/files/WKZMruMEn6x8ZP1JqODf" alt="" width="133"><figcaption><p>Newman</p></figcaption></figure>

***

## Pynt's Integration with Newman

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview) suit, Pynt allows seamless integration with Newman.

Pynt for Newman allows you to integrate advanced API security testing directly into your command-line workflows. By combining the power of Newman with Pynt, you can automate security scans alongside your regular API tests, ensuring that each API run is thoroughly tested for vulnerabilities.

With Pynt’s context-aware security testing capabilities, you can enhance your Postman collections with automated security checks, all executed via Newman. This integration is perfect for teams looking to streamline their security testing within their existing CI/CD processes, providing a seamless way to ensure that your APIs are protected against potential threats.

After each run, Pynt generates detailed reports that highlight any security risks found during testing, giving you the insights needed to address vulnerabilities promptly. By integrating Pynt with Newman, you can maintain the flexibility and efficiency of your command-line testing while significantly boosting your API security.

***

## Setup

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).

***

## Run Pynt CLI Command for Newman

### Basic usage

```bash
pynt newman --collection <path to collection>
```

### Required arguments

```
--collection - Postman collection file name
```

### Optional arguments

{% code overflow="wrap" fullWidth="false" %}

```
--environment - Postman environment file name (support multiple files)
--reporters output results to json
--host-ca - path to the CA file in PEM format to enable SSL certificate verification for pynt when running through a VPN.
--return-error - 'all-findings' (warnings, or errors), 'errors-only', 'never' (default), 
```

{% endcode %}

***

## Example

```bash
wget https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat.postman_collection.json
pynt newman --collection goat.postman_collection.json
```

***

## mTLS Support (Pynt binary only)

Pynt newman supports testing APIs that require mutual TLS (mTLS), allowing you to validate security for endpoints that enforce client certificate authentication.

To run a security test on an mTLS-protected API using Pynt Newman, use the `--ssl-client-cert`, `--ssl-client-key`, and `--ssl-ca-cert` flags to provide the necessary certificates.

#### Example

```bash
pynt newman --collection collection/goat-mtls.postman_collection.json \
  --tls-client-cert certs/client-bundle.pem \
  --tls-client-key certs/client.key \
  --host-ca certs/root.crt \
```

#### Arguments

* `--tls-client-cert` — Path to the client certificate (PEM format, can include full chain)
* `--tls-client-key`— Path to the client private key
* `--host-ca`— Path to the CA certificate used to validate the server certificate

## Specifying Environment variables (Pynt binary only)

To define environment variables for the collection via the command line in a key=value format, use the `--newman-env-var` flag. You can specify one variable per flag, or include multiple flags wrapped in quotes. For example:

{% code overflow="wrap" fullWidth="false" %}

```bash
pynt newman --collection goat.postman_collection.json \\ 
--newman-env-var="key1=test1,env2=test" --newman-env-var v1=v2
# This will run the collection with the following env vars:
# key1=test1
# env2=test
# v1=v2
```

{% endcode %}

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for TestRunner (ReadyAPI CLI)

Run Pynt API security tests from the ReadyAPI TestRunner

## **What is ReadyAPI TestRunner?**

{% hint style="info" %}
💡 [**ReadyAPI testrunner**](https://support.smartbear.com/readyapi/docs/functional/running/automating/about.html) is the command-line utility for running API tests in ReadyAPI. It allows you to execute functional, security, and performance tests directly from the CLI.
{% endhint %}

<figure><img src="/files/90Vbt401HKLkKtyqVfW8" alt="" width="375"><figcaption><p>ReadyAPI</p></figcaption></figure>

***

## Pynt's Integration with ReadyAPI TestRunner

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview) suit, Pynt allows seamless integration with any ReadyAPI tests.

Pynt can leverage the traffic generated by the ReadyAPI functional tests to perform a comprehensive API security test.

***

## Quick start

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).
3. Then, continue with the below example.

***

## Example

In this example, we will use [`pynt command`](/documentation/api-security-testing/pynt-cli-modes/pynt-command-cli-mode) to wrap the testrunner command. the proxy parameters must be added to route testrunner through Pynt: `-Dhttp.proxyHost` and `-DhttpProxyPort`&#x20;

See the following example:

```bash
$ pynt command --cmd './testrunner.sh -r -a -j -I /tmp/Project-1-readyapi-project.xml -Dhttp.proxyHost=127.0.0.1 -Dhttp.proxyPort=6666'
```

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt with Testing Frameworks

Enhance your security testing with Pynt’s seamless integration into popular frameworks like Go, Pytest, Jest, RestAssured, and Selenium.

{% hint style="success" %}
🚀 **At a Glance**: Pynt integrates effortlessly with popular testing frameworks like **Selenium, RestAssured, and Pytest**, allowing security tests to run alongside functional tests in any environment.
{% endhint %}

## Pynt CLI Integration with API Testing Frameworks

Pynt is **agnostic** to the testing framework, meaning it fits seamlessly into your existing workflows, whether you're testing APIs, backend services, or frontend components.

***

## Advantages of Pynt’s Agnostic Integration

{% hint style="info" %}
💡 **Automation Across Frameworks**: No matter the framework you use, Pynt automates security testing in your CI/CD pipeline, ensuring that all APIs are tested for vulnerabilities alongside functionality.
{% endhint %}

{% hint style="info" %}
🔍 **Adaptable to Any Tool**: Pynt integrates with any testing framework, so you don’t need to change your development process. Whether it's  **Selenium, RestAssured or, Pytest**, Pynt adds security testing seamlessly.
{% endhint %}

***

## Supported Frameworks

* [**Selenium**](/documentation/security-testing-integrations/pynt-with-testing-frameworks/pynt-for-selenium) for UI testing
* [**RestAssured**](/documentation/security-testing-integrations/pynt-with-testing-frameworks/pynt-for-rest-assured) for API testing
* [**Jest**](/documentation/security-testing-integrations/pynt-with-testing-frameworks/pynt-for-jest) for JavaScript testing
* [**Pytest**](/documentation/security-testing-integrations/pynt-with-testing-frameworks/pynt-for-pytest) for API testing
* [**Go**](/documentation/security-testing-integrations/pynt-with-testing-frameworks/pynt-for-go) for backend services
* [**JMeter**](/documentation/security-testing-integrations/pynt-with-testing-frameworks/pynt-for-jmeter) for API performance testing

Pynt’s flexibility ensures security tests run without disrupting your current workflows.

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for Cypress

### Overview

Using Cypress for end-to-end testing in combination with Pynt for automated API security testing is a powerful approach to enhance the security of your web applications.

As part of its API security testing suite, Pynt allows integration with Cypress to automate security scans within your test suites to detect and mitigate vulnerabilities effectively.

### Prerequisites

Before integrating Pynt with Cypress, make sure Pynt's [prerequisites](https://docs.pynt.io/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met and follow the instructions to [install Pynt CLI](https://docs.pynt.io/documentation/onboarding/getting-started).

### How to Run Pynt with Cypress

Pynt allows you to run API Security tests from Cypress E2E tests using `pynt command`.

#### Basic Command

To run Pynt with Cypress, use the following command:

```bash
pynt command --cmd "npx cypress run"
```

This will execute your Cypress tests while Pynt captures all API traffic and performs security analysis.

#### Running Specific Test Files

To run a specific test file with Pynt:

```bash
pynt command --cmd "npx cypress run --spec cypress.spec.cy.js"
```

Or for tests in subdirectories:

```bash
pynt command --cmd "npx cypress run --spec cypress/e2e/api-tests.cy.js"
```

#### Example with Options

Here's a complete example with common Pynt options:

```bash
pynt command --cmd "npx cypress run" \
     --test-name "Cypress E2E Security Tests" \
     --application-name "My Application"
```

### Configuration Options

#### Self-Signed Certificates

If your client is. validating SSL and can accept self-signed certificates, use the `--self-signed` flag:

```bash
pynt command --cmd "npx cypress run" --self-signed
```

#### Custom CA Certificate

If your client needs a specific certificate, provide the path to it with `--ca-path`:

```bash
pynt command --cmd "npx cypress run" --ca-path /path/to/certificate.pem
```

#### Application Configuration

Link your scan to a specific application:

```bash
pynt command --cmd "npx cypress run" --application-name "My Web App"
```

#### Test Naming

Use the `--test-name` flag to give your security scan a meaningful name:

```bash
pynt command --cmd "npx cypress run" --test-name "Production E2E Security Tests"
```

#### Allow Errors

To continue security scanning even when tests fail:

```bash
pynt command --cmd "npx cypress run" --allow-errors
```

### Goat Example:

Here's a comprehensive example demonstrating Pynt with Cypress:

Download the test files:

{% file src="/files/XUo74WbfjMB0jYl61kiV" %}

{% file src="/files/UD48BHOvNNkFfRVokrq3" %}

Run Pynt

```bash
pynt command --cmd "npx cypress run --spec cypress.spec.cy.js"
```

This will start a Pynt scan on Goat APIs, result should look like:

<figure><img src="/files/cSmiJ876EdJvBuSlJUxX" alt=""><figcaption></figcaption></figure>


# Pynt for pytest

Integrate Pynt with pytest to enhance API security testing. Automate security scans within your pytest test suites to detect and mitigate vulnerabilities effectively.

## **What is Pytest?**

{% hint style="info" %}
💡 [**pytest**](https://pytest.org/) is a powerful testing framework for Python applications, designed for simple unit tests as well as complex functional testing. It supports fixtures, parameterized testing, and assertions, making it highly adaptable for a variety of testing needs. With its easy-to-read syntax and extensive plugin ecosystem, pytest helps streamline the testing process for Python developers, ensuring robust and maintainable test suites.
{% endhint %}

<figure><img src="/files/VYMBewyo8l18mNWUbLAb" alt="" width="188"><figcaption><p>PyTest</p></figcaption></figure>

***

## **Pynt's integration with pytest**

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview) suit, Pynt allows seamless [integration](broken://pages/ehealt8LVTt8DWD89CXX) with any Pytest API testing.

By integrating Pynt with pytest, you can leverage the power of this vast platform while enhancing your API security. Pynt automatically generates context-aware security tests based on your pytest test scripts, enabling you to identify vulnerabilities early in the development cycle and reduce the risk of security issues in production.

***

## Quick start

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).
3. Then, continue with the below example.

***

## Example

[goat\_functional\_test.py](https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat_functional_test.py) is a python based tester for goat (our vulnerable application) that we use to test the functionality of goat, we run it with:&#x20;

```sh
pytest goat_functional_test.py
```

Now, to run Pynt on it, we run:

```bash
pynt command --cmd "pytest goat_functional_test.py"
```

***

## SSL Support

### Automatic Self-signed certificates

Pynt can automatically set your pytest to use self signed certificate. use the flag `--self-signed`

```bash
pynt command --cmd "<your test command>" --self-signed
```

If your functional test is enforcing SSL certificate verification (e.g. https) you will need to provide Pynt a certificate, If your client need a specific certificate, provide the path to it with `--ca_path`

***

### Manually providing certificates

```sh
pynt command --cmd "<your test command>" --ca-path <path to certificate file>
```

If your client does not use a specific certificate you will need to generate a certificate file and provide it to Pynt:

***

### Generate a certificate (Linux)

1\) Download [make\_certificate.sh](https://raw.githubusercontent.com/pynt-io/pynt/main/command/make_certificate.sh)

2\) Download [openssl.cnf](https://raw.githubusercontent.com/pynt-io/pynt/main/command/openssl.cnf)

3\) `chmod +x make_certificate.sh`

4\) Generate the certificate: `./make_certificate.sh`&#x20;

***

### Run Pynt with the generated certificate

Use the export REQUESTS\_CA\_BUNDLE before your command to instruct your functional test to use the new certificate and provide the path ti the certificate with --ca-path to instruct Pynt to use the generated certificate.

{% code overflow="wrap" %}

```sh
pynt command --cmd "export REQUESTS_CA_BUNDLE=rootCA.crt && python3 <your command here>" --ca-path rootCA.pem
```

{% endcode %}

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for .NET (xUnit)

Integrate Pynt with xUnit to enhance API security testing in .NET environments. Automate security scans within your test suites to detect and mitigate vulnerabilities as part of your CI/CD pipeline.

### What is xUnit?

💡 xUnit is a widely-used testing framework for .NET applications, known for its extensibility, simplicity, and integration with Visual Studio. It supports async tests, shared context, and rich assertions—making it ideal for unit, integration, and functional testing. xUnit helps ensure code correctness and reliability through automated and structured test execution.

***

### xUnit and Pynt Integration

Pynt integrates seamlessly with .NET test projects using xUnit. By observing traffic from your functional test executions, Pynt generates security tests that simulate real-world attacks and help identify critical vulnerabilities in your APIs.

This enables your .NET team to shift security testing left—during development—not after deployment.

***

### Quick Start

1. **Prepare your .NET environment**

   Ensure you have the [.NET SDK](https://dotnet.microsoft.com/download) installed (version 6 or later is recommended).
2. **Install Pynt container**

   Follow the [Pynt installation guide](https://docs.pynt.io/) to install and run the Pynt container.
3. **Clone or write your xUnit-based functional tests**

   You can use your existing API test suite, or follow the example below.

***

### Example

We’ve created a sample vscode project that tests login and transaction access for goat sample APIs.

Download it here:

[ApiTest.cs](https://raw.githubusercontent.com/pynt-io/pynt/refs/heads/main/goat_functional_tests/.net/ApiTest.cs)

[ApiTests.csproj](https://raw.githubusercontent.com/pynt-io/pynt/refs/heads/main/goat_functional_tests/.net/ApiTests.csproj)

Run the tests normally with:

```
dotnet test
```

To run Pynt on this test suite:

```
pynt command --cmd "dotnet test"
```

This will:

* Intercept traffic from your functional tests
* Automatically generate security test cases
* Report vulnerabilities like Broken Auth, IDOR, and more

***

### SSL Support

#### 🔐 Manually Providing Certificates

If your HttpClient configuration requires a specific CA certificate:

```
pynt command --cmd "dotnet test" --ca-path <path to certificate file>
```

If no certificate exists, generate one:

**Generate a certificate (Linux/macOS)**

1. Download [`make_certificate.sh`](https://raw.githubusercontent.com/pynt-io/pynt/main/command/make_certificate.sh)
2. Download [`openssl.cnf`](https://raw.githubusercontent.com/pynt-io/pynt/main/command/openssl.cnf)
3. Make the script executable:

   ```
   chmod +x make_certificate.sh
   ```
4. Run the script:

   ```
   ./make_certificate.sh
   ```

Then run your test with the generated certificate:

```
pynt command --cmd "dotnet test" --ca-path rootCA.pem
```

***

### 💡 Pynt CLI Troubleshooting

If you're encountering issues with Pynt's CLI, visit the [Pynt CLI Troubleshooting Guide](https://docs.pynt.io/troubleshooting) for solutions and tips.

***

### 💬 Still Need Help?

For questions or help, reach out to the [Pynt Community Support](https://community.pynt.io/) or join our Slack workspace.

***


# Pynt for Playwright

Integrate Pynt with Playwright to enable automated API security testing alongside your end-to-end browser tests.

### What is Playwright?

{% hint style="info" %}
💡 Playwright is a powerful framework for automating modern web applications across Chromium, Firefox, and WebKit. It is widely used for E2E testing, providing rich features like headless mode, multiple browser support, and network interception. Playwright is ideal for simulating real-world user behavior in CI environments.
{% endhint %}

<figure><img src="https://playwright.dev/img/playwright-logo.svg" alt="" width="188"><figcaption></figcaption></figure>

#### Pynt’s Integration with Playwright

As part of its dynamic API security suite, Pynt integrates with Playwright by observing the traffic generated during test execution. By running Playwright tests behind Pynt’s proxy, the APIs invoked during test flows are captured and analyzed for vulnerabilities.

***

> Pynt works by intercepting HTTP(S) traffic. It launches your test script with a local proxy and then analyzes the captured API interactions.

***

### Configuring Proxy in Playwright

When `RUNNING_FROM_PYNT=true`(set automatically by Pynt CLI, you will need to export it for Pynt Binary)  you should configure the browser to route traffic through Pynt’s proxy with the following configuration:

```javascript
    launchOptions.proxy = {
      server: 'http://127.0.0.1:6666',
      bypass: '<-loopback>'
    };
```

And ignore TLS errors :

```javascript
  const launchOptions = {
    headless: false,
    args: ['--ignore-certificate-errors']
  };
```

Here's a Java Script example with all configurations:

```js
(async () => {
  const useProxy = process.env.RUNNING_FROM_PYNT === 'true';

  const launchOptions = {
    headless: false
  };

  if (useProxy) {
    launchOptions.proxy = {
      server: 'http://127.0.0.1:6666',
      bypass: '<-loopback>'
    };
  }

  const browser = await chromium.launch(launchOptions);
  const page = await browser.newPage();
  
  // Actual playwright test here ...
  
  await context.close();
  await browser.close();
})();
```

***

### Example: Running Pynt against DVWA

DVWA (Damn Vulnerable Web Application) is a good demo target for Pynt + Playwright integration.

This example shows how to setup DVWA and run a short playwright test with **Pynt** to find the **MySQL Injection vulnerability**&#x20;

1. **Run DVWA locally via Docker**:

   ```bash
   docker run -it --rm -p 80:80 vulnerables/web-dvwa
   ```
2. **Download DVWA Playwright files**:
   * [test.js](https://raw.githubusercontent.com/pynt-io/pynt/refs/heads/main/DVWA%20examples/Bitbucket/test.js) - the test script
   * [package.json](https://raw.githubusercontent.com/pynt-io/pynt/refs/heads/main/DVWA%20examples/Bitbucket/package.json)
3. **Setup:**&#x20;

```bash
npm install
npx playwright install
```

4. **Run Pynt:**

```bash
pynt command --cmd "npm run test" --captured-domains "*localhost*"
```

The scan should look like this:

<figure><img src="/files/mvxxegUzqQw7dqurcRsy" alt=""><figcaption><p>Pynt scan in progress</p></figcaption></figure>

### Understanding the Results

Once your test finishes, Pynt will scan all APIs it observed during the Playwright test session. The results Will look like this:

<figure><img src="/files/bBd9CTr0qfj0b9gjY3oL" alt=""><figcaption><p>Pynt report showing the MySQL Injection</p></figcaption></figure>

***

### 💬 Need Help?

For further assistance, visit the Pynt CLI Troubleshooting Guide or ask the community on Pynt Community Support.


# Pynt for Selenium

Integrate Pynt with Selenium to enhance API security testing. Automate security scans within your Selenium test suites to detect and mitigate vulnerabilities effectively.

## **What is Selenium?**

{% hint style="info" %}
💡 [**Selenium**](https://www.selenium.dev/) is a widely-used framework for automating web browsers. It allows developers to automate browser interactions, making it ideal for testing web applications. With Selenium, you can simulate user actions and verify UI functionality across different browsers.
{% endhint %}

<figure><img src="/files/7CZhe8zTAVBR614ApUCL" alt="" width="188"><figcaption><p>Selenium</p></figcaption></figure>

***

## **Pynt's Integration with Selenium**

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview) suit, Pynt allows seamless integration with Selenium.\
Using Selenium for UI testing in combination with Pynt for automated API security testing is a powerful approach to enhance the security of your web applications. Here’s a step-by-step guide on how you can integrate Selenium with Pynt to create automated API security tests:

<figure><img src="/files/bXPHYeeF5M7KLZHWzMgW" alt=""><figcaption><p>Pynt with Selenium</p></figcaption></figure>

***

## Setup Pynt

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt conainer [here](/documentation/api-security-testing/how-to-install-pynt-cli).
3. This integration is based on [`pynt command`](/documentation/api-security-testing/pynt-cli-modes/pynt-command-cli-mode) in which Pynt is running the command given in the `--cmd` argument through a proxy, captures the traffic and runs API security tests on the APIs seen in the traffic. Continue with the below example.

***

## Setup Selenium for integrating with Pynt

Since the Chromium browser does not honor the `HTTPS_PROXY` environment variables set by Pynt, you need to manually configure your Selenium test to use the Pynt proxy.

To configure Selenium chrome web driver to go through a Proxy, add the following lines to your webdriver setup:

```python
chrome_options.add_argument('--proxy-server=http://127.0.0.1:6666')
chrome_options.add_argument('--proxy-bypass-list=<-loopback>')
chrome_options.add_argument("--ignore-certificate-errors")
```

Here's an example of a Python function that creates a Chrome WebDriver with a proxy, utilizing the `RUNNING_FROM_PYNT` environment variable set by the Pynt CLI to conditionally apply the proxy settings:

```python
def get_webdriver(browser):
    if browser == "CHROME":
        chrome_options = webdriver.ChromeOptions()
        pynt = os.environ.get("RUNNING_FROM_PYNT", "")
        if pynt == "True":
            # This section is only when running with Pynt
            chrome_options.add_argument('--proxy-server=http://127.0.0.1:6666')
            chrome_options.add_argument('--proxy-bypass-list=<-loopback>')
            chrome_options.add_argument("--ignore-certificate-errors")
    
        return webdriver.Chrome(options=chrome_options) 
```

***

## Example

Here's a detailed guide to setting up and running a Selenium test with crAPI (Completely Ridiculous API), a vulnerable web application created by OWASP, and then using this test to run Pynt API Security tests to find Business Logic vulnerabilities in crAPI.

### Setting up our target (crAPI)

This [link](https://github.com/OWASP/crAPI?tab=readme-ov-file#quickstart-guide) includes instructions for setting up crAPI on Windows, Mac, or Linux. For example in linux the install flow is:

```bash
curl -o docker-compose.yml https://raw.githubusercontent.com/OWASP/crAPI/main/deploy/docker/docker-compose.yml

docker-compose pull

docker-compose -f docker-compose.yml --compatibility up -d
```

Wait for crAPI to start, verify by going to [`http://localhost:8888` ](<http://localhost:8888 >)

***

### Setting up the Selenium test

Download crapi\_selenium.py from here:

```
wget https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/selenium/crapi_selenium.py
wget https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/selenium/requirements.txt
pip install requirements.txt
```

***

### Running the Selenium test

`python3 crapi_selenium.py`

Flow of the selenium test:

1. Setup the chrome driver
2. Register a new user
3. Register a new vehicle for that user
4. Login
5. Go to dashboard and view vehicle location
6. Close the chrome driver
7. Repeat the same process for another user

***

### Running the Selenium test with Pynt

Now that the selenium test is setup we can run Security tests:

```
pynt command --cmd "python3 sel.py" --no-proxy-export
```

You should see the Selenium test executes and then Pynt will begin to scan the APIs and show the report once its done, the flag -`-no-proxy-export` is telling Pynt not to export `HTTPS_PROXY` environment variables as it will cause Selenium configuration traffic to also be captured by Pynt.

***

### Understanding the results

The UI test focuses solely on the login and dashboard pages, rather than covering the entire crAPI application. Despite this limitation, it provides sufficient data for Pynt to detect a Business Logic vulnerability (BOLA) related to vehicle location. This specific vulnerability enables an attacker to query the locations of vehicles owned by other users.

<figure><img src="/files/ZtOFyrKs3sCxV2gdZki6" alt=""><figcaption><p>Results summary example</p></figcaption></figure>

<figure><img src="/files/c9vDvmnOLFg2vA9053gm" alt=""><figcaption><p>API vulnerabilities example</p></figcaption></figure>

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for Rest Assured

Integrate Pynt with Rest Assured to enhance API security testing. Automate security scans within your Rest Assured test suites to detect and mitigate vulnerabilities effectively.

## **What is RestAssured?**

{% hint style="info" %}
💡 [**RestAssured**](https://rest-assured.io/) is a popular Java-based library for testing RESTful APIs. It simplifies the process of validating and verifying API responses by providing an easy-to-use syntax for making API calls. With RestAssured, you can test APIs seamlessly in your Java projects.
{% endhint %}

<figure><img src="/files/TrKD787tDy369kMeBHkV" alt="" width="140"><figcaption><p>RestAssured</p></figcaption></figure>

***

## **Pynt's integration with RestAssured**

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview) suit, Pynt allows seamless integration with any RestAssured test.

By integrating Pynt with RestAssured, you can leverage the power of this vast platform while enhancing your API security. Pynt automatically generates context-aware security tests based on your RestAssured test scripts, enabling you to identify vulnerabilities early in the development cycle and reduce the risk of security issues in production.\
If your functional tests are based on Java Rest Assured, you can use pynt command to run API Security tests from these functional tests.

***

## Quick start

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).
3. Then, continue with the below example.

***

## Example

[goat-rest-assured](https://github.com/pynt-io/pynt/tree/main/goat_functional_tests/goat-rest-assured) is a Rest Assured based project of a functional test of goat vulnerable application. we run it with:

```
mvn test
```

Now, to run Pynt on it, we run:

```sh
pynt command --cmd "mvn -Dhttp.proxyHost=127.0.0.1 -Dhttp.proxyPort=6666 test" 
```

***

## SSL support

If your functional test is enforcing SSL certificate verification (e.g. https) you will need to provide Pynt a certificate, If your client need a specific certificate, provide the path to it with `--ca_path`

```sh
pynt command --cmd "<your test command> -Dhttp.proxyHost=127.0.0.1 -Dhttp.proxyPort=6666 -Dhttps.proxyHost=127.0.0.1 -Dhttps.proxyPort=6666" --ca-path <path to certificate file>
```

If your client does not use a specific certificate you will need to generate a certificate file and provide it to Pynt:

***

### Generate a certificate (Linux)

1\) Download [make\_certificate.sh](https://raw.githubusercontent.com/pynt-io/pynt/main/command/make_certificate.sh)

2\) Download [openssl.cnf](https://raw.githubusercontent.com/pynt-io/pynt/main/command/openssl.cnf)

3\) `chmod +x make_certificate.sh`

4\) Generate the certificate: `./make_certificate.sh`&#x20;

5\) create a trust-store, you will be prompted with entering a password for the key store  (from now on  we will assume the trust-store is called test.jks and the password is test123456):

```
keytool -importcert -file ./rootCA.crt -keystore test.jks 
```

***

### Run Pynt with generated certificate

{% code overflow="wrap" %}

```bash
pynt command --cmd "mvn test -Dhttp.proxyHost=127.0.0.1 -Dhttp.proxyPort=6666 -Dhttps.proxyHost=127.0.0.1 -Dhttps.proxyPort=6666 -Djavax.net.ssl.trustStore=./test.jks -Djavax.net.ssl.trustStorePassword=test123456" --ca-path rootCA.pem
```

{% endcode %}

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for Jest

Integrate Pynt with jest to enhance API security testing. Automate security scans within your jest test suites to detect and mitigate vulnerabilities effectively.

## **What is Jest?**

{% hint style="info" %}
💡 [**Jest**](https://jestjs.io/) is a popular JavaScript testing framework designed for testing React and other JavaScript applications. It offers features like snapshot testing, mocking, and coverage reports to simplify and enhance your testing workflows.
{% endhint %}

<figure><img src="/files/PZlPp1Sx4cCgeulJkW5v" alt="" width="225"><figcaption><p>Jest</p></figcaption></figure>

***

## **Pynt's integration with Jest**

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview) suite, **Pynt** integrates seamlessly with Jest, allowing automated security testing in JavaScript environments.

If your functional tests are based on java script framework like jest, you can use Pynt command to run API Security tests from these functional tests.

***

## Quick start

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).
3. Then, continue with the below example.

***

## Example

[jest.test.py](https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/jest.test.js) is a javascript-based tester for goat (our vulnerable application) that we use to test the functionality of goat, we run it with:&#x20;

```sh
npm test
```

Now, to run Pynt on it, we run:

```bash
pynt command --cmd "npm test"
```

<figure><img src="/files/zURm237AmA1xMa1d3LQl" alt=""><figcaption><p>Pynt for Jest example</p></figcaption></figure>

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for Go

Integrate Pynt with Go to enhance API security testing. Automate security scans within your Go test suites to detect and mitigate vulnerabilities effectively.

## **What is Go?**

{% hint style="info" %}
💡 [**Go**](https://golang.org/) is a statically typed, compiled programming language designed for simplicity, reliability, and efficiency. Popular for building scalable web services, Go's concurrency features make it ideal for large-scale applications. It’s used extensively in cloud infrastructure, microservices, and API development. With its performance and ease of use, Go is a top choice for backend developers looking to build high-performance APIs and systems.
{% endhint %}

<figure><img src="/files/ERcLslaxceNaGS8W27P7" alt="" width="188"><figcaption><p>Golang</p></figcaption></figure>

***

## **Pynt's integration with Go**

Pynt’s [API security testing](/documentation/api-security-testing/security-testing-overview) suite integrates seamlessly with Go, enabling secure, high-performance development and testing of APIs in Go applications.

If your functional tests are written in Go, you can use Pynt command to run API Security tests from these functional tests.

***

## Quick start

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).
3. Then, continue with the below example.

***

## Example

[test\_goat.go](< https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat_test.go>) is a go based tester for goat (our vulnerable application) that we use to test the functionality of goat, here is how to run it:

1. Get test\_goat.go

{% code overflow="wrap" %}

```bash
curl https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat_test.go -o goat_test.go
```

{% endcode %}

2. Get testify

```bash
go get github.com/stretchr/testify
```

3. go mod

```bash
go mod init goat_test.go
go mod tidy
```

4. Check that functional test works

```bash
go test
```

5. Run Pynt on functional test

```bash
pynt command --cmd "go test"
```

***

## SSL Support

#### Automatic Self-signed certificates

Pynt can automatically set your go test to use self signed certificate. use the flag `--self-signed`

```bash
pynt command --cmd "<your test command>" --self-signed
```

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for JMeter

Integrate Pynt with Go to enhance API security testing. Automate security scans within your JMeter test suites to detect and mitigate vulnerabilities effectively.

## **What is JMeter?**

{% hint style="info" %}
💡 [**JMeter**](https://jmeter.apache.org/) is a widely-used open-source tool for load testing and performance measurement of web applications and APIs. It simulates a high number of users interacting with an application, helping developers assess scalability and performance. JMeter supports various protocols, including HTTP, FTP, JDBC, and more, making it a versatile tool for testing the robustness and stability of applications under heavy load conditions.
{% endhint %}

<figure><img src="/files/U62WYq5R3Nibw114dxUW" alt="" width="134"><figcaption><p>JMeter</p></figcaption></figure>

***

## **Pynt's integration with JMeter**

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview) suite, **Pynt** integrates seamlessly with JMeter, enabling automated security testing alongside performance assessments.

If you use JMeter for your API performance tests, you can utilize pynt command to run API Security tests from these performance tests.

***

## **Quick start**

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).
3. To integrate Pynt with JMeter, use the following command:

{% code fullWidth="false" %}

```bash
pynt command --cmd "./jmeter -E http -H 127.0.0.1 -P 6666 -n -t <your jmx file>"
```

{% endcode %}

This command directs JMeter to execute the specified test plan (`test.jmx`) in non-GUI mode and logs the results to `results.jtl`.&#x20;

The `-E http -H 127.0.0.1 -P 6666` parameters tell JMeter to direct its traffic to the proxy started by the pynt command during scanning.

Continue with the below example.

***

## Example&#x20;

1. Download goat.jmx example from [here](https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat.jmx) or get it:

```bash
wget https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat.jmx
```

2. Run it with Pynt:&#x20;

```bash
pynt command --cmd "jmeter -E http -H 127.0.0.1 -P 6666 -n -t goat.jmx"
```

<figure><img src="/files/QgJ4PHcQY9FPNUE0nlt4" alt=""><figcaption><p>Pynt for JMeter Example</p></figcaption></figure>

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt on CI/CD

Integrate Pynt with your CI/CD pipelines for automated API security testing. Ensure robust protection by seamlessly incorporating Pynt's security scans into your continuous integration and delivery wo

{% hint style="success" %}
🚀 **At a Glance**: Pynt is a breakthrough technology that performs **contextual, automated, and continuous PenTesting** as part of your CI/CD pipeline. By seamlessly integrating with your workflow, Pynt ensures real-time security testing for your APIs as they evolve.
{% endhint %}

Pynt integrates seamlessly into **any CI/CD pipeline**, enabling automated API security testing at every stage of the development process. Pynt supports [**Jenkins**](/documentation/security-testing-integrations/pynt-on-ci-cd/pynt-for-jenkins), [**GitLab**](/documentation/security-testing-integrations/pynt-on-ci-cd/pynt-for-gitlab), [**GitHub Actions**](/documentation/security-testing-integrations/pynt-on-ci-cd/pynt-for-github-actions), and [**AzureDevOps**](/documentation/security-testing-integrations/pynt-on-ci-cd/pynt-for-azure-devops-pipelines) as verified examples but is agnostic to the CI/CD tool being used.

***

### Benefits of CI/CD Integration

#### Automated Security Scans

With Pynt, you can run automated security scans triggered by various actions:

* **Following API changes**
* **Following a code change that affects API calls**
* **Following a functional test change**

Pynt dynamically learns your application behavior, expanding security tests as your functional tests grow, with no need for manual adjustments.

***

#### DevSecOps Integration

Pynt allows **DevSecOps** teams to implement automated PenTests within the CI/CD pipeline in just a few clicks. Once configured, Pynt detects and addresses vulnerabilities in real-time, offering flexible options to either **stop the build** or **reflect results**.

***

### Continuous PenTesting

Pynt provides **continuous PenTesting**, reducing the risk of deploying insecure code by expanding the test suite automatically as your functional tests evolve.

***

{% hint style="info" %}
💡 **Need Help?** For questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# How to get Pynt ID for CI/CD Authentication

Learn how to obtain your Pynt ID for CI/CD authentication. Follow these simple steps to integrate Pynt into your CI/CD pipelines and secure your APIs effectively.

{% hint style="info" %}
💡 **Getting Your Pynt ID**: To set up authentication in CI/CD pipelines, you'll need your Pynt ID. Ensure that this ID is securely stored for use in automation and pipeline configurations.
{% endhint %}

## Why do I need Pynt-Id

Pynt-Id is your authentication token to Pynt platform it is needed to integrate Pynt into your CI/CD pipeline.

***

## How should I get Pynt-Id

There are two ways to get Pynt ID:

***

### Via Pynt platform

Go to Settings -> General -> Pynt ID and copy it.

<figure><img src="/files/eSq2eJ6XDbAxvlU3Dbju" alt=""><figcaption><p>Copy PyntID from SaaS</p></figcaption></figure>

***

### Via Pynt CLI

In Pynt CLI, Run:

```bash
pynt pynt-id
```

(You will be asked to login on your first time running Pynt)

<figure><img src="/files/XBbwn0ElfjUlSU0ZHXHE" alt=""><figcaption><p>Copy PyntID from Pynt CLI</p></figcaption></figure>

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for GitHub Actions

Integrate Pynt with GitHub Actions for automated API security testing. Enhance your CI/CD pipeline by adding Pynt’s robust security scans to your GitHub Actions workflows.

## **What is GitHub Actions?**

{% hint style="info" %}
💡 [**GitHub Actions**](https://github.com/features/actions) allows you to automate workflows for building, testing, and deploying code. With native integration into GitHub repositories, you can trigger workflows based on events like pushes, pull requests, and schedule automation tasks.
{% endhint %}

<figure><img src="/files/wb3QT3I3PvimOnkC4XJg" alt="" width="113"><figcaption><p>GitHub Actions</p></figcaption></figure>

***

## Pynt's integration with GitHub Actions

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview), Pynt allows seamless [integration](/documentation/security-testing-integrations/pynt-on-ci-cd) with GitHub Actions.

Pynt for GitHub Actions enables you to seamlessly integrate powerful API security testing into your GitHub Actions CI/CD pipelines. By incorporating Pynt into your GitHub Actions workflows, you can automate comprehensive security scans with every build, ensuring that your APIs are protected from vulnerabilities throughout the development process. Pynt’s integration with GitHub Actions is designed to be straightforward, allowing you to enhance your security posture without disrupting your existing CI/CD practices.

***

## GitHub Actions Configuration

* Copy your [Pynt ID](/documentation/security-testing-integrations/pynt-on-ci-cd/how-to-get-pynt-id-for-ci-cd-authentication) into action secrets in your GitHub:

<figure><img src="/files/W38GqT8mysIMdnrbdMv7" alt=""><figcaption><p>Add pynt-id to a Github secret</p></figcaption></figure>

* Make sure Python installed on the agent.
* Add Pynt to your workflow, see the following example of a job in a Github workflow that runs Pynt on our goat vulnerable application:

{% code overflow="wrap" %}

```yaml
name: Example pynt yml 
on: 
  workflow_dispatch:
    inputs: 
      comment: 
        type: string 
        default: "API Security tests"

env:
  PYNT_ID: ${{ secrets.YOURPYNTID }}

jobs:
 api-security:
  runs-on: ubuntu-latest

  steps: 
    - name: install pynt cli
      run: | 
        python3 -m pip install --upgrade pyntcli 
    - name: get goat collection 
      run: | 
        curl https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat.postman_collection.json -o goat.json 
    - name: run pynt with newman integration 
      run: | 
        pynt newman --collection goat.json --reporters
```

{% endcode %}

***

## Controlling the return code from Pynt

`pynt newman` and `pynt command` have an optional flag `--severity-level`

With this flag, you have granular control over whether Pynt returns an error code (non zero) in the event of findings. Use this flag to control when Pynt will break the CI/CD run, allowed values are:

```
'all', 'medium', 'high', 'critical', 'none' (default) 
```

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for Azure DevOps Pipelines

Integrate Pynt with Azure DevOps for automated API security testing. Enhance your CI/CD pipeline by adding Pynt’s robust security scans to your Azure DevOps workflows.

## **What is Azure DevOps?**

{% hint style="info" %}
💡 [**Azure DevOps**](https://azure.microsoft.com/en-us/services/devops/) is a suite of development tools that provide CI/CD capabilities, version control, and project management. It supports building, testing, and deploying applications across cloud and on-premises environments.
{% endhint %}

<figure><img src="/files/rC7H65OrjHT8vb2zUVkb" alt="" width="196"><figcaption><p>Azure DevOps</p></figcaption></figure>

***

## Pynt integration with Azure DevOps

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview), Pynt allows seamless [integration](/documentation/security-testing-integrations/pynt-on-ci-cd) with Azure DevOps.

Pynt for Azure DevOps enables you to seamlessly integrate powerful API security testing into your Azure DevOps CI/CD pipelines. By incorporating Pynt into your Azure DevOps workflows, you can automate comprehensive security scans with every build, ensuring that your APIs are protected from vulnerabilities throughout the development process. Pynt’s integration with Azure DevOps is designed to be straightforward, allowing you to enhance your security posture without disrupting your existing CI/CD practices.

***

## Azure DevOps Configuration

* Copy your [Pynt ID](/documentation/security-testing-integrations/pynt-on-ci-cd/how-to-get-pynt-id-for-ci-cd-authentication) into the pipeline variable and store it as a secret:

<figure><img src="/files/0NLVgwqRmvx9iEntPehT" alt=""><figcaption><p>Storing Pynt ID</p></figcaption></figure>

* Make sure Python installed on the agent.
* Add Pynt to your pipeline. See the following example of a job in an Azure pipeline that runs Pynt on our goat vulnerable application:

{% code overflow="wrap" %}

```yaml
trigger:
- main

pool: 
  name: test

steps:
- script: python3 -m pip install --upgrade pyntcli
  displayName: 'Install pynt cli'

- script: curl https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat.postman_collection.json -o goat.json 
  displayName: 'Get goat collection'

- script: |
    export PYNT_ID = $(PYNT_ID)
    pynt newman --collection goat.json --reporters --severity-level critical
  displayName: 'Run pynt with newman integration '
```

{% endcode %}

### Pynt command not found

If you get pynt command not found error it means that pip install folder is not in your path. add the following to the last step:

```yaml
- script: |
    export PYNT_ID = $(PYNT_ID)
    
    # Get the user base bin directory
    BIN_PATH=$(python -m site --user-base)/bin
      
    # Add it to the PATH
    export PATH=$BIN_PATH:$PATH
      
    # Verify that it's been added
    echo "Updated PATH: $PATH"
    
    pynt newman --collection goat.json --reporters --severity-level critical
  displayName: 'Run pynt with newman integration '
```

***

## Controlling the return code from Pynt

`pynt newman` and `pynt command` have an optional flag `--severity-level`

With this flag, you have granular control over whether Pynt returns an error code (non zero) in the event of findings. Use this flag to control when Pynt will break the CI/CD run, allowed values are:

```
'all', 'medium', 'high', 'critical', 'none' (default) 
```

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for GitLab

Integrate Pynt with GitLab for automated API security testing. Enhance your CI/CD pipeline by adding Pynt’s robust security scans to your GitLab workflows.

## **What is GitLab?**

{% hint style="info" %}
💡 [**GitLab**](https://about.gitlab.com/) is a comprehensive DevOps platform that provides a unified CI/CD solution, enabling teams to plan, develop, and deploy applications seamlessly. GitLab’s built-in CI/CD tools allow for automation, version control, and monitoring.
{% endhint %}

<figure><img src="/files/XvFEm3eVAFnZ9mn8kgxG" alt="" width="139"><figcaption><p>GitLab</p></figcaption></figure>

***

## Pynt's integration with GitLab

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview), Pynt allows seamless [integration](/documentation/security-testing-integrations/pynt-on-ci-cd) with GitLab.

Pynt for GitLab enables you to seamlessly integrate powerful API security testing into your GitLab CI/CD pipelines. By incorporating Pynt into your GitLab workflows, you can automate comprehensive security scans with every build, ensuring that your APIs are protected from vulnerabilities throughout the development process. Pynt’s integration with GitLab is designed to be straightforward, allowing you to enhance your security posture without disrupting your existing CI/CD practices.

***

## GitLab Configuration

Copy your [Pynt ID](/documentation/security-testing-integrations/pynt-on-ci-cd/how-to-get-pynt-id-for-ci-cd-authentication) into a variable in your GitLab variables

Settings -> CICD -> Variables

<figure><img src="/files/We2z1Te60mUOuU4NLEb9" alt=""><figcaption><p>Add Pynt-ID to a GitLab variable</p></figcaption></figure>

Add Pynt to you workflow, see following example of a job in GitLab workflow that runs Pynt on our goat vulnerable application:

```yaml
stages:
  - security_scan

run_pynt:
  stage: security_scan
  image: python:3.11
  script:
    # Get and install Pynt Binary 
    - wget https://cdn.pynt.io/binary-release/install.sh
    - chmod +x install.sh
    - ./install.sh
    - cd ~/.pynt/bin/
    # Get sample pytest
    - wget https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat_functional_test.py    
    - python3 -m pip install --upgrade pip
    - pip install pytest
    - pip install requests
    # Run Pynt on the pytest file
    - export PYNT_ID=$pyntid
    - ./pynt command --cmd "python3 -m pytest goat_functional_test.py" --severity-level none

  artifacts:
    paths:
      - ~/.pynt/results
    expire_in: 1 hour

```

***

## Controlling the return code from Pynt

`pynt newman` and `pynt command` have an optional flag `--severity-level`

With this flag, you have granular control over whether Pynt returns an error code (non zero) in the event of findings. Use this flag to control when Pynt will break the CI/CD run, allowed values are:

```
'all', 'medium', 'high', 'critical', 'none' (default) 
```

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for Jenkins

Integrate Pynt with Jenkins for automated API security testing. Enhance your CI/CD pipeline by adding Pynt’s robust security scans to your Jenkins workflows.

## **What is Jenkins?**

{% hint style="info" %}
💡 [**Jenkins**](https://www.jenkins.io/) is an open-source automation server used for continuous integration and delivery. Jenkins allows developers to build, test, and deploy software by automating tasks in customizable pipelines.
{% endhint %}

<figure><img src="/files/JfHSmuuzCeTDR4s0L6OR" alt="" width="188"><figcaption><p>Jenkins</p></figcaption></figure>

***

## Pynt's integration with Jenkins

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview), Pynt allows seamless [integration](/documentation/security-testing-integrations/pynt-on-ci-cd) with Jenkins.

Pynt for Jenkins enables you to seamlessly integrate powerful API security testing into your Jenkins CI/CD pipelines. By incorporating Pynt into your Jenkins workflows, you can automate comprehensive security scans with every build, ensuring that your APIs are protected from vulnerabilities throughout the development process. Pynt’s integration with Jenkins is designed to be straightforward, allowing you to enhance your security posture without disrupting your existing CI/CD practices.

***

## Jenkins Configuration

Add [Pynt ID](/documentation/security-testing-integrations/pynt-on-ci-cd/how-to-get-pynt-id-for-ci-cd-authentication) to Jenkins environment variables:

<figure><img src="/files/76brHLpkwaiFih6kru0D" alt=""><figcaption></figcaption></figure>

* Make sure Python installed on the agent.
* An example for a Jenkins job running Pynt newman against goat collection:

```bash
echo "Pynt API Security testing"

# Using venv is a good practice
python3 -m venv myenv
. myenv/bin/activate

pip install pyntcli
export PATH=$PATH:/var/lib/jenkins/.local/lib/python3.10/site-packages

curl https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat.postman_collection.json -o goat.json 
pynt newman --collection goat.json --reporters
cat pynt_results.json

deactivate

```

***

## Controlling the return code from Pynt

`pynt newman` and `pynt command` have an optional flag `--severity-level`

With this flag, you have granular control over whether Pynt returns an error code (non zero) in the event of findings. Use this flag to control when Pynt will break the CI/CD run, allowed values are:

```
'all', 'medium', 'high', 'critical', 'none' (default) 
```

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for Bitbucket pipelines

Integrate Pynt with Bitbucket Pipelines for automated API security testing. Enhance your CI/CD pipeline by adding Pynt’s dynamic security scans to your Bitbucket workflows with minimal setup.

### What is Bitbucket Pipelines?

{% hint style="info" %}
💡 Bitbucket Pipelines allows you to automate workflows for building, testing, and deploying code directly from your Bitbucket repositories. With a YAML-based configuration, you can define pipelines that run on every push, pull request, or scheduled trigger.
{% endhint %}

***

#### Pynt’s Integration with Bitbucket Pipelines

As part of its API security testing suite, Pynt allows seamless integration with Bitbucket Pipelines.

Pynt for Bitbucket Pipelines enables you to automatically perform API security tests within your CI/CD workflow. This integration captures real API traffic during test or application runs, then analyzes it for security vulnerabilities such as BOLA, misconfigured headers, authentication issues, and more.&#x20;

***

### Bitbucket Pipelines Configuration

Add your `PYNT_ID` as a repository variable or workspace variable in Bitbucket:

* Go to **Repository Settings > Repository Variables**
* Add [PYNT\_ID](/documentation/security-testing-integrations/pynt-on-ci-cd/how-to-get-pynt-id-for-ci-cd-authentication):

  <figure><img src="/files/mWeAJM05VqUf5kfOcHH3" alt=""><figcaption></figcaption></figure>

***

#### Example: Running Pynt with Playwright

In this example we are running a Bitbucket pipeline that:

* Installs playwright dependencies
* Installs [Pynt Binary](/documentation/api-security-testing/how-to-install-pynt-binary-linux-only)&#x20;
* Runs [DVWA](https://github.com/digininja/DVWA) as a target for the scan
* Performs an API security scan with a playwright script, find MySQL vulnerability.
* Upload results to Pynt dashboard under "dvwa\_example" application (application will be created if the running user has Admin role, if the user has "User" role, have an Admin create this application in Pynt dashboard)&#x20;

:information\_source: Example files can be found [here](https://github.com/pynt-io/pynt/tree/main/DVWA%20examples/Bitbucket)

Here is how the *bitbucket-pipelines.yml* is configured:&#x20;

```yaml
image: mcr.microsoft.com/playwright:v1.44.0-jammy

pipelines:
  default:
    - step:
        name: Run DVWA and Playwright Tests
        services:
          - dvwa
        caches:
          - node
        script:
          - npm install
          - npx playwright install --with-deps
          - echo "Waiting for DVWA to be ready..."
          - until curl -sSf http://localhost:80/login.php > /dev/null; do sleep 3; done
          - echo "DVWA is up!"
          - npm run test
          - export PYNT_ID=$PYNT_ID          
          - wget https://cdn.pynt.io/binary-release/install.sh
          - chmod +x install.sh
          - ./install.sh
          - export RUNNING_FROM_PYNT=true
          - ~/.pynt/bin/pynt command --cmd "npm run test" --application-name dvwa_example

definitions:
  services:
    dvwa:
      image: vulnerables/web-dvwa
```

***

### Controlling the return code from Pynt

`pynt newman` and `pynt command` support an optional flag `--severity-level` to control CI behavior when findings are detected.

This flag determines when Pynt will return a non-zero exit code and break the pipeline:

```
Allowed values:
'all', 'medium', 'high', 'critical', 'none' (default)
```

**Example:**

```bash
pynt command --cmd "node your-playwright-script.js" --severity-level critical
```

This will break the CI pipeline only if Pynt detects findings of critical severity

***

### 💡 Need Help?

For questions or troubleshooting:

* Visit the Pynt CLI Troubleshooting Guide
* Ask the community at Pynt Community Support


# Pynt with Burp Suite

Enhance Burp Suite with Pynt for advanced API security testing. Integrate Pynt to automate and extend your security testing capabilities within Burp Suite.

## **What is Burp Suite?**

{% hint style="info" %}
💡 [**Burp Suite**](https://portswigger.net/burp) is a leading web vulnerability scanner used by security professionals for penetration testing of web applications. It provides tools for scanning, testing, and analyzing vulnerabilities, and supports both manual and automated security testing workflows. Burp Suite is widely used for identifying issues such as injection flaws, authentication vulnerabilities, and other security concerns in web applications.
{% endhint %}

<figure><img src="/files/wC9k840qjn33Xw780ZLc" alt="" width="178"><figcaption><p>Burp Suite</p></figcaption></figure>

***

## Pynt's integration with Burp Suite

As part of its [API security testing](/documentation/api-security-testing/security-testing-overview), Pynt allows seamless [integration](broken://pages/ZmOFLrYOIcNpTOCjzK65) with Burp.

Integrating Pynt with Burp Suite enhances your API security testing by adding automated context-aware security scans to your testing process. With Pynt, you can automate vulnerability assessments within Burp Suite, ensuring that your APIs are continuously monitored and protected against emerging threats. Pynt's integration with Burp Suite provides detailed security reports, helping you quickly identify and address critical vulnerabilities in your APIs. This powerful combination of tools enables you to maintain a secure and resilient API environment, streamline your testing workflow, and deliver secure applications with confidence.

***

## Use Pynt listen as an upstream proxy of Burp&#x20;

Run pynt listen and set it to capture the domains of the traffic that you want Pynt to scan:

`pynt listen --captured-domains <domains>`

#### Setting Upstream Proxy in Burp Suite

To configure Burp Suite to use an upstream proxy, follow these steps:

1. Open Burp Suite and navigate to the **Proxy** tab.
2. Click on the **Options** sub-tab.
3. Scroll down to the **Upstream Proxy Servers** section.
4. Click on the **Add** button.
5. In the dialog that appears, enter the details of the upstream proxy:
   * **Destination host**: Leave this as `*` to apply to all destinations, or specify specific hosts.
   * **Proxy host**: Enter the IP address of Pynt listen `127.0.0.1`
   * **Proxy port**: Enter the port number of Pynt listen `6666`
6. Click **OK** to save your upstream proxy configuration.

Now, Burp Suite will route all external traffic through Pynt proxy. Hit enter to trigger Pynt scan.

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt with Browsers

Secure your APIs with Pynt's browser integration. Automate API security testing directly from your web browser for seamless and effective protection against vulnerabilities.

{% hint style="success" %}
🚀 **At a Glance**: Pynt’s browser integration allows you to conduct **real-time API security tests** directly from your browser with just a few clicks. It monitors API traffic, automatically generating security tests to identify vulnerabilities as you interact with APIs.
{% endhint %}

## Pynt Browsers Integration

Pynt integrates effortlessly with your web browsers, providing a powerful way to conduct **API security testing** directly from your browsing environment. Whether developing, testing, or interacting with APIs, Pynt’s browser integration allows you to run comprehensive security scans with just a few clicks.

***

## Benefits of Browsers Integration

Pynt’s browser integration is **user-friendly** and efficient, allowing you to identify and address vulnerabilities in real-time without leaving your browser. It automatically generates security tests based on live API traffic, ensuring continuous monitoring and protection against emerging threats.

***

## Who Benefits?

* **Developers**: Seamless testing during development.
* **Testers**: Easy integration with API testing tools.
* **Security Professionals**: Immediate security insights and reports.

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt for Firefox Browser

Integrate Pynt with Firefox for seamless API security testing. Automate and enhance your API protection directly within the Firefox browser.

{% hint style="success" %}
🚀 **At a Glance**: Pynt integrates directly with **Firefox**, enabling real-time API security testing as you browse. This seamless integration monitors API traffic, automatically generating context-aware security tests.
{% endhint %}

***

## Capturing traffic from Firefox Browser&#x20;

Pynt can also conduct an API security scan on traffic generated from Firefox in an interactive mode, following these steps:

* Configure Firefox to route traffic through Pynt.
* Run Pynt using the command: `pynt listen --captured-domains <domain of the APIs that need to be tested>`.
* Browse the site that will be tested by Pynt.
* Press Enter on Pynt to start the scan.

***

## Steps to Run Pynt with Firefox

Use the following steps to integrate Pynt with Firefox browser:

***

### **Configure Firefox to Record Traffic**

* Open Firefox and go to the settings to configure the proxy through which Pynt can capture the traffic.

<figure><img src="/files/FwOSfAM3sfZ0gtwXuGJj" alt=""><figcaption><p>Configure Proxy in Firefox</p></figcaption></figure>

If your target is *localhost* as in the example, go to about:config and modify the `network.proxy.allow_hijacking_localhost` parameter to **True**

<figure><img src="/files/JRyPe76yDe7Khfw5Fg98" alt=""><figcaption><p>Enable Firefox to route localhost traffic to proxy</p></figcaption></figure>

***

### **Configure Firefox to Import Pynt's proxy certificate**&#x20;

* The first time you execute `pynt listen`, Pynt stores the certificates in `~/.pynt/cert`.
* Import the `mitmproxy-ca-cert.cer` into Firefox

<figure><img src="/files/OmHFIDQeJVDMPXfKUo9Z" alt=""><figcaption><p>Import Pynt's proxy certificate</p></figcaption></figure>

<figure><img src="/files/vqHMmH9vNj0BaM5FHTq3" alt=""><figcaption><p>Download certificate</p></figcaption></figure>

***

## Example on OWASP crAPI

For this example we will use [`Pynt listen`](/documentation/api-security-testing/pynt-cli-modes/pynt-listen-cli-mode) and set it to capture localhost traffic:

```bash
pynt listen --captured-domains localhost
```

<figure><img src="/files/YpaL1xKhlIEcuYuczZG3" alt=""><figcaption></figcaption></figure>

For this example we will test with traffic to [OWASPs crAPI ](https://github.com/OWASP/crAPI)application running locally on localhost:8888

Now on Firefox set the url to <http://localhost:8888> and do various actions on crAPI web pages

<figure><img src="/files/6e9OPS3xINHH0b4oHsTy" alt=""><figcaption><p>Firefox examle</p></figcaption></figure>

After finishing browsing the site, return to the terminal where Pynt is running and press Enter to start the Pynt scan.

<figure><img src="/files/XyoYzQF3w1cX7H7JmQjc" alt=""><figcaption><p>Pynt for Firefox example</p></figcaption></figure>

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Live Traffic Connectors

Enhance API security testing and discovery with Pynt’s seamless Live Traffic integrations. Capture real-time API traffic effortlessly for deeper security insights

{% hint style="success" %}
🚀 **At a Glance**: Pynt seamlessly integrates with Live Traffic sources like **eBPF in Kubernetes** and **AWS Traffic Mirroring**, enabling real-time API security testing and discovery without modifying your application.
{% endhint %}

***

## Advantages of Pynt’s Agnostic Integration

{% hint style="info" %}
💡 **Automated Security from Live Traffic**: Pynt passively captures **real-time API traffic** using **connectors**, enabling **continuous security testing and discovery** without modifying your application or CI/CD pipeline.
{% endhint %}

{% hint style="info" %}
🔍 **Works with Any Environment**: Whether running in **Kubernetes, AWS, or hybrid cloud**, Pynt integrates seamlessly with your existing infrastructure—no changes to your application code or testing frameworks required.
{% endhint %}

***

## Supported C**onnectors**

* [eBPF](/documentation/security-testing-integrations/live-traffic-connectors/ebpf) for K8s
* [Traffic mirroring](/documentation/security-testing-integrations/live-traffic-connectors/traffic-mirroring) for AWS ALB

Pynt’s flexibility ensures security tests run without disrupting your current workflows.

***

{% hint style="info" %}
💡 **Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# eBPF

## Introduction

This document provides a technical overview of how Pynt leverages **eBPF** to **capture real-time HTTP traffic, generate HAR files**, and seamlessly integrate with Pynt’s SaaS platform for **deep API security insights**.

By implementing **eBPF-based live traffic**, Pynt enables **comprehensive API visibility**—identifying both **known and shadow APIs** while ensuring minimal system overhead.

## Architecture Diagram

<figure><img src="/files/4YxPnVlSXYRwD60H2yBN" alt=""><figcaption></figcaption></figure>

## Installation & Deployment

### **Access to Deployment Manifests**

To deploy Pynt’s **eBPF Live Traffic integration**, please **contact our team**. We will provide:

* **Kubernetes manifests** for seamless installation.
* A **detailed README** with setup instructions.

### **Guided Deployment Support**

Our security experts are available to assist you with:

* Customizing filters, storage limits, and network configurations.
* Ensuring smooth integration into your Kubernetes environment.


# Pynt for Kubernetes Quick Prerequisites Guide for the scanner

##

### Overview

The Pynt agent is the container that performs the Pynt scan inside your cluster. By default, it will be created in the **`pynt`namespace**. You can modify this namespace to fit your organization’s standards if needed.

### Access Control

* Make sure that **RBAC permissions** allow the Pynt agent in its namespace (default `pynt`) to access resources in the **other namespaces** where your APIs and microservices run.

### Networking (Egress)

* Ensure the agent can reach your APIs and required external endpoints (such as Pynt Cloud SaaS if applicable).
* DNS access must be allowed.
* If you run with strict NetworkPolicies, confirm that egress rules permit the Pynt agent to reach both your internal namespaces and any necessary external hosts.

### Resource Requirements

* The Pynt agent requires at least **2GB of memory requests** to run reliably. Ensure your cluster has sufficient resources before deploying.

***

**Tip**: Start with the default installation in the `pynt` namespace, validate connectivity, then adjust namespace, resources, and permissions as per your org’s policies.


# Key Components

## **eBPF Sniffer**

**Purpose:** Intercepts HTTP traffic by hooking into key system calls (`accept`, `read`, `write`, `close`) at the kernel level.\
**Deployment:** Runs as a **DaemonSet** in Kubernetes, ensuring coverage across all nodes.\
**Value:** Captures API traffic in **near real-time** with **low overhead** and **no code instrumentation**.

## **RabbitMQ (Message Queue)**

**Purpose:** Acts as a **scalable message broker** between the Sniffer and Aggregator.\
**Deployment:** Runs as a **Kubernetes Deployment** in the same cluster.<br>

## Aggregator

**Purpose:** Collects, filters, and **deduplicates HTTP session data** before generating HAR files.\
**Deployment:** Runs as a **Kubernetes Deployment**, pulling data from the Sniffer via **RabbitMQ**.\
**Responsibilities:**

* **Filtering** irrelevant traffic.
* **Deduplicating** repeated sessions.
* **Storing** the last X sessions in memory.
* **Providing an API** to generate HAR files on demand.

## **Attacker Container (Soon)**

**Purpose:** Accesses generated HAR files for **automated security scanning** and API testing.\
**Deployment:** Runs as a **sidecar container** within the Aggregator pod.\
**Benefit:** Enables **seamless vulnerability testing** **without extra network hops**.

## Security & Trust Considerations

### **Minimal System Footprint**

eBPF operates **in a sandboxed environment** at the **kernel level**, ensuring **system stability** with **minimal overhead**.

### **Controlled Access & Compliance**

**Strict access controls** allow only authenticated users and **designated microservices** to request HAR files.

**Filtered storage policies** prevent the retention of unnecessary or sensitive data.

### **End-to-End Data Protection**

**All communication is encrypted** between the Sniffer, Aggregator, and RabbitMQ.

Data remains contained **within your Kubernetes cluster**, ensuring **isolation and security compliance**.


# Traffic Mirroring

## Overview

Pynt Traffic Capture is a powerful solution for real-time application traffic monitoring. This infrastructure automatically captures traffic from your Application Load Balancers (ALBs), providing an API catalog of your application's behavior and security.

## Key Features

* **Real-time Traffic Analysis**: Capture and analyze traffic in real-time without impacting your application performance
* **High Availability**: Deployed across multiple Availability Zones for maximum reliability
* **Secure by Design**:
  * Runs in your network
  * Minimal required permissions
  * Secure parameter handling
* **Easy Deployment**: One-click deployment using AWS CloudFormation
* **Automatic Recovery**: Auto Scaling Group ensures continuous operation
* **Flexible Configuration**: Customize instance types, security settings, and upload intervals

## Architecture

The Pynt Traffic Capture infrastructure consists of:

1. **Traffic Capture Components**:
   * Sniffer ([Suricata](https://github.com/OISF/suricata)): Captures and processes network traffic
   * [Traffic Mirroring](https://docs.aws.amazon.com/vpc/latest/mirroring/what-is-traffic-mirroring.html): Manages traffic mirroring sessions with ALBs
   * Pynt's service aggregates and uploads the traffic metadata to Pynt's SaaS platform
2. **Infrastructure Components**:
   * Auto Scaling Group: Ensures high availability and automatic recovery
   * Security Groups: Controls access to the capture infrastructure
   * IAM Roles: Provides necessary permissions with least privilege

## Prerequisites

Before deploying, ensure you have:

1. An AWS account with appropriate permissions
2. A VPC with at least two private subnets in different Availability Zones
3. An EC2 key pair for SSH access
4. The following information:
   * VPC ID
   * List of subnet IDs (at least 2 recommended for high availability)
   * Pynt API key, **please ask Pynt's team!**
   * Application ID
   * CIDR block for allowed UDP traffic
5. CloudFormation template (`pynt-traffic-capture.yaml`). **Please ask Pynt's team!**

## Deployment Options

### Option 1: AWS Console (Recommended for First-Time Users)

1. Go to the AWS CloudFormation console.
2. Click "Create stack"
3. Choose "Template is ready"
4. Upload the template file
5. Fill in the required parameters
6. Click through to create the stack

### Option 2: AWS CLI&#x20;

1. Create a parameters file (`parameters.json`):

```json
[
  {
    "ParameterKey": "VpcId",
    "ParameterValue": "vpc-xxxxxxxx"
  },
  {
    "ParameterKey": "SubnetIds",
    "ParameterValue": "subnet-xxxxxxxx,subnet-yyyyyyyy"
  },
  {
    "ParameterKey": "KeyName",
    "ParameterValue": "your-key-pair"
  },
  { 
    "ParameterKey": "AllowedIPs",
    "ParameterValue": "0.0.0.0/0"
  },
  {
    "ParameterKey": "AllowedCidr",
    "ParameterValue": "0.0.0.0/0"
  },
  {
    "ParameterKey": "ApiKey",
    "ParameterValue": "your-api-key"
  },
  {
    "ParameterKey": "ApplicationId",
    "ParameterValue": "your-application-id"
  }
]
```

2. Deploy using AWS CLI:

```bash
aws cloudformation create-stack \
  --stack-name pynt-traffic-capture \
  --template-body file://pynt-traffic-capture.yaml \
  --parameters file://parameters.json \
  --capabilities CAPABILITY_IAM
```

## Configuration Options

| Parameter                 | Description                                                                                  | Default    |
| ------------------------- | -------------------------------------------------------------------------------------------- | ---------- |
| VpcId                     | The VPC ID where resources will be created and where your application to monitor will exist. | -          |
| SubnetIds                 | List of subnet IDs (at least 2 recommended)                                                  | -          |
| KeyName                   | EC2 KeyPair for SSH access                                                                   | -          |
| AllowedIPs                | IP range allowed for SSH access                                                              | 0.0.0.0/0  |
| AllowedCidr               | A CIDR block for UDP traffic. The CIDR block should be from the VPC you specified.           | 0.0.0.0/0  |
| InstanceType              | EC2 instance type                                                                            | t3a.medium |
| ApiKey                    | Your Pynt API key                                                                            | -          |
| ApplicationId             | Your Pynt Application ID                                                                     | -          |
| InitialUploadDelaySeconds | Initial delay before data upload                                                             | 60         |
| UploadIntervalSeconds     | Interval between data uploads                                                                | 60         |

## Security Considerations

* **Network Security**:
  * Instances run in your network
  * SSH access is restricted to a specific IP range
  * UDP traffic is restricted to a specific CIDR block
* **IAM Security**:
  * Minimal required permissions
  * Role-based access control
  * Secure handling of sensitive parameters
* **Instance Security**:
  * Automatic security updates
  * Secure bootstrapping process
  * Encrypted EBS volumes

## Maintenance

### Updating the Stack

To update the stack with new parameters or configuration:

```bash
aws cloudformation update-stack \
  --stack-name pynt-traffic-capture \
  --template-body file://pynt-traffic-capture.yaml \
  --parameters file://parameters.json \
  --capabilities CAPABILITY_IAM
```

### Deleting the Stack

To remove the Pynt Traffic Capture infrastructure:

```bash
aws cloudformation delete-stack --stack-name pynt-traffic-capture
```

## Support

For assistance with deployment or troubleshooting, please get in touch with Pynt Support at [support@pynt.io](mailto:support@pynt.io?subject=SSO+Setup).


# Advanced Pynt Examples

Explore advanced Pynt examples including integration with HAR files, Standalone containers, and cURL. Enhance your API security testing with these powerful use cases.

## Advanced Pynt Examples

Advanced Pynt examples showcase the versatility and power of Pynt’s API security testing capabilities across different scenarios and tools. By integrating Pynt with **HAR files**, **Standalone containers**, and **cURL**, you can tailor your security testing workflows to fit your specific needs.

***

### Integration with Standalone Containers

{% hint style="info" %}
💡 **Standalone Containers**: Running Pynt without the CLI allows for use in non-traditional Docker environments, enabling you to scale and automate security tests across multiple instances with ease.
{% endhint %}

***

### Integration with HAR Files

{% hint style="info" %}
💡 **HAR Files**: Import HAR (HTTP Archive) files directly into your testing suite to analyze captured API traffic and run security tests based on real-world data, ensuring a comprehensive assessment.
{% endhint %}

***

### Integration with cURL

{% hint style="info" %}
💡 **cURL Integration**: Incorporate Pynt into your command-line workflows with cURL, enabling automatic security testing for HTTP requests made in your scripts or automation processes.
{% endhint %}

***

These advanced Pynt examples demonstrate how Pynt’s flexibility enhances API security testing across various tools and environments.

***

{% hint style="info" %}
💡 **Need Help?** For questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt as a Standalone Container

Run Pynt as a standalone container without the CLI for isolated and scalable API security testing. Ensure consistent and efficient protection across your development environments.

{% hint style="success" %}
🚀 **At a Glance**: Pynt’s standalone container mode allows you to run the Pynt container without the CLI, making it ideal for systems like Kubernetes or container orchestration platforms. In this mode, you control Pynt through its APIs and route HTTP traffic through the container for security testing.
{% endhint %}

***

## Standalone container mode

Pynt container can run without the CLI, facilitating its use in various deployment scenarios beyond traditional Docker-based environments. This mode is particularly useful for systems leveraging Kubernetes or similar container orchestration platforms.

This mode is based on [Pynt command](/documentation/api-security-testing/pynt-cli-modes/pynt-command-cli-mode), but here the user is required to run the Pynt container, control it through APIs, and route the http traffic through the container.

There are two step needed for this integration:

**Run the Pynt Container:** This involves setting up and running the Pynt container. Pynt can operate as a stand-alone server, as long as it setup correctly.&#x20;

**Control via APIs & Route HTTP Traffic:** After deploying the Pynt container, you will need to manage it through its APIs. Additionally, route your HTTP traffic through the container to have Pynt scan the traffic.

***

## How to run the Pynt **container**

`Image:`

* `ghcr.io/pynt-io/pynt:v1-latest`

`Ports:`

* `6666` - Pynt proxy port
* `5001` - port for API commands to Pynt server

`Environment variables:`

* `PYNT_ID="$PYNT_ID"` - Pynt credentials, [how to get it](/documentation/security-testing-integrations/pynt-on-ci-cd/how-to-get-pynt-id-for-ci-cd-authentication)
* `PYNT_SAAS_URL="https://api.pynt.io/v1"` - Pynt Platform's URL

`Flags:`

{% hint style="info" %}
When the application identifier is not provided, the scan results will not be saved in any application, and you can see it in the global views. The best practice is to provide the identifier.
{% endhint %}

* `--application-id` - [Application View Overview](/documentation/applications-view/application-view-overview#where-can-i-find-the-application-id-1)
* `--application-name` - Your existing application name or a new one. (the application will be created automatically if it does not exist)

Here is an example of running Pynt server using docker:

{% code overflow="wrap" %}

```bash
docker run -e PYNT_ID="$PYNT_ID" -p 6666:6666 -p 5001:5001 --rm ghcr.io/pynt-io/pynt:v1-latest proxy --application-name my-app
```

{% endcode %}

***

<figure><img src="/files/ZtSC8cuRcwEmYZyuoZ07" alt=""><figcaption><p>Running Pynt as standalone container</p></figcaption></figure>

## How to control Pynt container

Once the Pynt container is running in your environment, run the Pynt scan by the following these steps:

1. Set a few environment variables pointing to the container (or to your local machine when exposing the ports):

   ```bash
   export PYNT_SERVER_BASE=http://127.0.0.1
   export PYNT_SERVER_URL=$PYNT_SERVER_BASE:5001
   ```
2. To activate the Pynt proxy, make a call to the `/api/proxy/start` endpoint. Once activated, Pynt will listen on port 6666 for incoming traffic. For example, you can use curl as follows:

   ```bash
   scan_output=$(curl -X PUT $PYNT_SERVER_URL/api/proxy/start)
   ```
3. Run your functional tests through the Pynt proxy. Pynt will read and analyze the traffic. For example, using Python Pytest:

   ```bash
   export HTTP_PROXY=$PYNT_SERVER_BASE:6666
   export HTTPS_PROXY=$PYNT_SERVER_BASE:6666
   pytest goat.py
   ```
4. To start a Pynt scan, you need to call the `/api/proxy/stop` endpoint, providing the `scan_id` in the message body. For example, you can use the following `curl` command:

   <pre class="language-bash" data-overflow="wrap"><code class="lang-bash">curl -X PUT $PYNT_SERVER_URL/api/proxy/stop -d "$scan_output" -H "Content-Type: application/json"
   </code></pre>
5. Optionally, you can pass the Application ID and Test Name for improved management of this scan in the Pynt platform. For example:

   <pre class="language-bash" data-overflow="wrap"><code class="lang-bash">scanId=$(echo $scan_output | jq -r .scanId)
   applicationId=xxxx
   testName="My Test Name"
   json_payload=$(printf '{"scanId": "%s", "applicationId": "%s", "testName": "%s"}' "$scanId" "$applicationId" "$testName")
   curl -X PUT $PYNT_SERVER_URL/api/proxy/stop -d "$json_payload" -H "Content-Type: application/json"
   </code></pre>

### Retrieving Scan Reports

After running a Pynt scan, you can retrieve the scan report by polling the `/api/report` endpoint using the scan ID. This process ensures that you get the final report once the scan is complete.

#### **Polling for Report Completion**

Since scans take time to process, you must continuously check the report status until the scan completes. The server returns:

* **202 (Accepted):** The scan is still in progress.
* **200 (OK):** The scan is complete, and the report is available.

#### **Retrieving the HTML Report**

The HTML report provides a human-readable summary of the scan results.

**Example using `curl`**

{% code overflow="wrap" %}

```bash
scanId=$(echo $scan_output | jq -r .scanId)
status_code=$(curl -o "pynt_report.html" -s -w "%{http_code}\n" "$PYNT_SERVER_URL/api/report?scanId=$scanId&format=html")
```

{% endcode %}

This command saves the report as `pynt_report.html`

***

## Controlling the return code from Pynt

Pynt container have an optional flag `--severity-level`

With this flag, you have granular control over whether Pynt returns an error code (3) in the event of findings. Use this flag to control when Pynt will break the CI/CD run, allowed values are:

```
'all', 'medium', 'high', 'critical', 'none' (default) 
```

***

#### **Retrieving the JSON Report**

The JSON report contains structured data about vulnerabilities, making it useful for integrations with other tools.

**Example using `curl`**

{% code overflow="wrap" %}

```bash
scanId=$(echo $scan_output | jq -r .scanId)
status_code=$(curl -o "pynt_report.json" -s -w "%{http_code}\n" "$PYNT_SERVER_URL/api/report?scanId=$scanId&format=json")
```

{% endcode %}

This command retrieves the scan results in JSON format and saves them as `pynt_report.json`

***

## Example: Pynt with Kubernetes

{% embed url="<https://github.com/pynt-io/pynt/tree/main/goat_functional_tests/k8s>" %}
Pynt for Kubernetes
{% endembed %}

***

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt with Prerecorded Har Files

Use Pynt with prerecorded HAR files to analyze and secure your APIs based on traffic data. Enhance your API security testing with detailed, traffic-based assessments.

{% hint style="success" %}
🚀 **At a Glance**: Pynt allows you to use **Prerecorded HAR Files** for API security testing, providing a powerful way to assess testing environments or real-world API traffic. By importing HAR files into Pynt, you can run comprehensive security scans on captured traffic data, ensuring the Pynt's security tests leverages actual API usage.
{% endhint %}

***

## What is HAR File

A HAR (HTTP Archive) file is a JSON-formatted file that logs a web browser's interaction with a site. It records all web requests and responses, including URLs, headers, body content, and the timing information for each resource. HAR files are used for analyzing network performance issues and troubleshooting website errors.

<figure><img src="/files/AGQ296jarp0JEtkycIUZ" alt="" width="64"><figcaption><p>har</p></figcaption></figure>

***

## How to Record HAR Files

Recording HAR files can be done using various methods, depending on the browser or tool you are using. Here are the most common ways:

***

### **Using Google Chrome**

1. Open the Chrome menu (three dots) and select **More tools > Developer tools**.
2. Go to the **Network** tab.
3. Check the **Preserve log** box to save all interactions.
4. Reproduce the issue you are encountering.
5. Right-click within the Network tab and choose **Save all as HAR with content**.

***

### **Using Mozilla Firefox**

1. Open the menu (three horizontal bars) and select **Web Developer > Network**, or press `Ctrl+Shift+E`.
2. Reproduce the issue on the site.
3. Click the **Save all as HAR** icon to export the HAR file.

***

### **Using Safari**

1. Go to **Safari > Preferences > Advanced** and check the **Show Develop menu in menu bar**.
2. From the **Develop** menu, select **Show Web Inspector**.
3. Click the **Network** tab and reproduce the issue.
4. Right-click the network items and select **Export HAR**.

***

### **Using Other Tools**

* **WebPageTest**: When running a test, select the **Chrome** tab and check the **Capture Network Log** option.
* **Fiddler**: Can capture network traffic and export it as a HAR file.
* **Charles Proxy**: Can also be used to generate HAR files from captured network traffic.

Each method varies slightly but ultimately serves the purpose of capturing web interactions to troubleshoot or analyze website performance issues.

***

## Setup

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).

***

## **Run Pynt CLI Command for HAR**

### Basic usage

```
pynt har --har <path to har file> --captured-domains <domain>
```

### Required arguments

{% code overflow="wrap" %}

```
--har - Path to har file
--captured-domains - Pynt will scan only these domains and subdomains. For all domains write "*"
```

{% endcode %}

### Optional arguments

{% code overflow="wrap" %}

```
--reporters - Output results to json
--application-id - Attach the scan to an application, you can find the ID in your applications area at app.pynt.io
--host-ca - Path to the CA file in PEM format to enable SSL certificate verification for pynt when running through a VPN.
```

{% endcode %}

***

## **How to run Pynt with HAR file**

For example, running Pynt on a HAR file of goat:

get the `goat.har` file [here](https://raw.githubusercontent.com/pynt-io/pynt/main/goat_functional_tests/goat.har)

Run Pynt:

```bash
pynt har --har goat.har --captured-domains  "*"
```

<figure><img src="/files/X2ZXpvcSETO8UlZddZty" alt=""><figcaption><p>Pynt with HAR example</p></figcaption></figure>

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Pynt with cURL

Integrate Pynt with cURL for seamless API security testing from the command line. Automate security scans directly within your cURL workflows.

{% hint style="success" %}
🚀 **At a Glance**: Pynt integrates effortlessly with **cURL**, allowing you to incorporate API security testing into your command-line workflows. By making HTTP requests with cURL, Pynt can automatically generate security tests and execute them without additional setup. This integration is perfect for users looking to automate security checks directly from scripts or command-line tools, ensuring that all requests are thoroughly tested for vulnerabilities.
{% endhint %}

***

## What is cURL?

[**cURL** ](https://curl.se/)is a widely used command-line tool that enables data transfer over various network protocols, including HTTP, HTTPS, FTP, and more. Developers and system administrators frequently use cURL to send requests, test APIs, download files, and debug network services. It supports a vast range of options for handling headers, authentication, and data formats, making it a flexible and powerful tool for network communication.

<figure><img src="/files/9XraQnBG2rSrLUp3awfj" alt="" width="188"><figcaption><p>cURL</p></figcaption></figure>

***

## Setup

1. First, make sure Pynt's [prerequisites](/documentation/api-security-testing/prerequisites-for-running-pynt-scans) are met.
2. Follow the instructions to install Pynt container [here](/documentation/api-security-testing/how-to-install-pynt-cli).

***

## Example of Pynt with cURL

Pynt can work even on a single curl line, just add the following:

1. `--proxy 127.0.0.1:6666`
2. `--insecure`&#x20;
3. `escape all " to '/"`

For example running on one request to goat application:

```bash
pynt command --cmd 'curl --location '\''http://44.202.3.35:6000/account'\'' \
--header '\''Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VySWQiOiJhYTc4NmI5ZS03NDZiLTQ4M2EtYTI2YS0xMDVlZjBmNDY2ZTYifQ.5wiIckUlguqJRUY36szfN0K3FLsfT34tXey_K4JPYIk'\'' \
 --insecure --proxy 127.0.0.1:6666'
```

***

{% hint style="info" %}
💡 **Pynt CLI Troubleshooting**: If you're encountering issues with Pynt's CLI, visit the [**Pynt CLI Troubleshooting Guide**](https://docs.pynt.io/documentation/api-security-testing/pynt-scans-troubleshooting/pynt-cli-troubleshooting) for solutions and troubleshooting tips.
{% endhint %}

{% hint style="info" %}
💡 **Still Need Help?** For any questions or troubleshooting, reach out to the [**Pynt Community Support**](https://www.pynt.io/community).
{% endhint %}


# Application View Overview

Uncover the power of Pynt's API Catalog! Explore our comprehensive overview to understand how Pynt enables seamless API discovery, risk assessment, and security testing.

Pynt's **Applications View** is part of [**Pynt's enterprise** **plan**](https://www.pynt.io/pricing)**.**

The applications view serves as a **central hub** for managing your applications to meet your API security needs.&#x20;

From API discovery to security testing, the application view provides a user-friendly interface for viewing your **applications** and their **API sources**, such as **API gateway, documentation,** and **testing.** This view allows you to understand their associated risks, and drill down to the individual **application dashboard**.

Customize your Pynt experience according to your applications and projects, set up integrations seamlessly, and ensure that your API security strategy aligns with your organization's requirements.

Access the applications view conveniently from the left menu pane.

### Application ID <a href="#where-can-i-find-the-application-id" id="where-can-i-find-the-application-id"></a>

The Application ID serves as a unique identifier for your application on the Pynt platform.&#x20;

It is utilized for various operations and information retrieval within the platform, such as linking scans and APIs to the application.

### Where can I find the application ID?&#x20;

<figure><img src="/files/VOPSEoik6sPHjnKvhIO8" alt=""><figcaption></figcaption></figure>


# Manage Applications

Effortlessly manage applications in your API Catalog with Pynt! Explore our guide on setting up and efficiently overseeing applications within your API Catalog.

Pynt's applications view is a comprehensive interface designed to facilitate efficient **management of applications** within an organization's API landscape. An application in Pynt represents a logical grouping of **one or more APIs**, each connected by a shared application login.

Let's consider a logistics and transportation organization managing two applications within Pynt:

1. Application: **Route Planning**
   * APIs:
     * Geolocation API: Provides real-time geolocation data for vehicles and delivery points.
     * Traffic Information API: Offers up-to-date traffic conditions to optimize route planning.
     * Route Optimization API: Calculates the most efficient delivery routes based on various factors.
2. Application: **Fleet Management**
   * APIs:
     * Vehicle Health API: Monitors and reports the health and status of each vehicle in the fleet.
     * Fuel Efficiency API: Provides data on fuel consumption and efficiency for each vehicle.
     * Maintenance Scheduling API: Helps schedule and track routine maintenance for the fleet.

In this context, the '**Route Planning**' application focuses on APIs related to optimizing delivery routes and ensuring timely and efficient transportation. On the other hand, the '**Fleet Management**' application deals with APIs that monitor the health and performance of the organization's vehicles. By managing these distinct sets of APIs under different applications, the logistics organization can maintain a well-organized and specialized API landscape to support its diverse operational needs.

The logistics organization benefits from the flexibility of Pynt, allowing it to integrate APIs from different sources, including API gateways and documentation. This enables efficient management and organization of APIs across **separate products and projects**, enhancing overall transparency and control within the organization's logistics and transportation services.

You should be able to [add ](/documentation/applications-view/manage-applications/add-application)and [delete](/documentation/applications-view/manage-applications/delete-application) applications, [edit the application's name](/documentation/applications-view/manage-applications/rename-application), [enter an individual application dashboard view](/documentation/applications-view/application-dashboard), and view the list of added applications from this view, as in the below example.

<figure><img src="/files/2XSsS8lVUGKIpRgvvCQd" alt=""><figcaption><p>Applications list example</p></figcaption></figure>


# Add Application

Effortlessly add applications with Pynt's intuitive setup. Streamline API discovery and security seamlessly.

Effortlessly add applications with Pynt's intuitive setup, making API security management easier than ever. Pynt's streamlined process guides you through adding your applications, ensuring that API discovery and security testing are seamlessly integrated into your workflow. Whether you're working with a single application or managing multiple APIs across different environments, Pynt's setup is designed to be user-friendly and efficient.

As soon as you add an application, Pynt automatically begins mapping and cataloging your APIs, providing a clear overview of your API landscape. This intuitive setup reduces the time and effort needed to get started, allowing you to focus on securing your APIs without the hassle of complex configurations.

With Pynt, you can ensure that your applications are protected from the moment they are added, leveraging powerful security testing tools that run in the background. Whether you're a developer, security professional, or part of a larger team, Pynt's seamless application setup helps you maintain robust API security effortlessly.

\
Create new applications by clicking on the '**Add**' button and entering your application name:

<figure><img src="/files/ARRZvxkCdCVxbTf2Fs0o" alt=""><figcaption><p>Add Application</p></figcaption></figure>


# Delete Application

Effortlessly delete applications with Pynt's intuitive setup. Streamline API discovery and security seamlessly.

Easily delete applications in Pynt with a few simple steps, ensuring your API security setup stays clean and organized. Pynt’s intuitive interface allows you to quickly remove any application from your dashboard, streamlining your workflow and keeping your focus on active projects. This efficient process helps maintain an up-to-date API security environment, free from outdated or unnecessary applications.

\
Remove applications with ease by clicking on the '**Delete**' from the '**Actions**' menu.&#x20;

Please note that removing an application will also unlink all connected sources and associated scans, if any. You will be prompted to approve the operation for confirmation.

<figure><img src="/files/LVKVxhGlrhociKCyB2Wu" alt=""><figcaption><p>Delete application</p></figcaption></figure>


# Rename Application

Effortlessly rename the application with Pynt's intuitive setup.

Quickly rename applications in Pynt with ease, helping you maintain a clear and organized API management system. Pynt's straightforward renaming feature allows you to update application names without disrupting your security setup, ensuring that your dashboard accurately reflects your active projects and API environment. This simple process keeps your workflow efficient and your API management tidy.\
\
Rename applications with ease by clicking on the '**Edit**' from the '**Actions**' menu.&#x20;

<figure><img src="/files/rsBvkrg3O0mihOT7JpcR" alt=""><figcaption><p>Rename the application</p></figcaption></figure>


# Manage Sources for API Discovery

Streamline your API Catalog with Pynt by efficiently managing sources! Explore our guide on setting up and overseeing sources within your API Catalog.

The sources management functionality empowers organizations to continuously update their API catalog by **integrating various sources**, ensuring an up-to-date and accurate security posture. Each API source is associated with a **specific application**, allowing for a tailored and focused approach to catalog management.

API sources can include diverse options such as [**API documentation**](/documentation/applications-view/manage-sources-for-api-discovery/source-categories/api-documentation), [**API gateways**](/documentation/applications-view/manage-sources-for-api-discovery/source-categories/api-gateways), [**live traffic**](/documentation/applications-view/manage-sources-for-api-discovery/source-categories/live-traffic),[ ***code repositories***](/documentation/applications-view/manage-sources-for-api-discovery/source-categories/code-repository), or Pynt API security [**testing**](/documentation/applications-view/manage-sources-for-api-discovery/source-categories/testing-api-security-scans) sources (discovered automatically by executring a scan).&#x20;

The flexibility extends further, enabling users to assign **multiple sources** of the same type to a single application. For example, an organization can link Swagger as a documentation API source and AWS Gateway as a production source to the same application. This enhances adaptability in managing their API landscape and enables Pynt to identify API security posture gaps effectively.

By leveraging 'Manage API Sources,' organizations can streamline the process of **cataloging APIs**, enhancing security, and ensuring that their API catalog remains dynamic and responsive to the evolving needs of their applications.

For each application, you can add sources directly from to application view or from the individual application page.


# Add Source

Effortlessly enhance your API catalog with Pynt! Add sources seamlessly using the 'Add Source' feature in the setup.

Easily add sources in Pynt to enhance your API security management. Pynt’s intuitive interface allows you to quickly integrate new data sources, providing a more comprehensive view of your API landscape. Whether it's adding a new scan, API documentation, or API catalog, Pynt makes it simple to bring in additional sources for security scanning and analysis. This streamlined process ensures that your API security is thorough and up-to-date, allowing you to monitor and protect your applications effectively.\
\
Link a new source to any application by clicking '**Add Source**' from the '**Actions**' menu or by clicking on the '**+**' icon of any one of the individual sources associated with the relevant application.

<figure><img src="/files/fVveuBtBf3lavGIzPFaM" alt=""><figcaption><p>Add source</p></figcaption></figure>


# Delete Source

Effortlessly enhance your API catalog with Pynt! Delete sources seamlessly using the 'Delete Source' feature in the setup.

Easily delete sources in Pynt, to keep your API security management clean and organized. Pynt’s user-friendly interface allows you to quickly remove any unnecessary sources, ensuring your focus remains on the most relevant data. This efficient process helps maintain an up-to-date and clutter-free security environment, allowing you to manage and protect your APIs more effectively.

\
Unlink a source from any application by clicking on the relevant source in the table and clicking on '**Delete Source**' on the opened form.

<figure><img src="/files/HCi1Z63xkvVlbhmNahMe" alt=""><figcaption><p>Delete source</p></figcaption></figure>


# View Source Info

Effortlessly enhance your API catalog with Pynt! View source information using the 'View Source' feature in the setup.

Effortlessly view source information in Pynt to gain detailed insights into your API security setup. With Pynt’s intuitive interface, you can quickly access and review data from your integrated sources, such as scans, documentation, or gateways. This feature allows you to monitor and analyze the status of your API security, ensuring that you have the most accurate and up-to-date information at your fingertips. Whether you need to check on a specific source or get a comprehensive overview, Pynt makes it easy to stay informed and in control of your API security environment.\
\
View source info for any application by **clicking on the relevant source** in the table.

You should be access detailed information about a source, including its **category**, specific **integration**, source **type**, and other **source-specific** **details**.

<figure><img src="/files/XPkLfubauCaePmmefJdN" alt=""><figcaption><p>View source info</p></figcaption></figure>


# Source Categories

Optimize your API catalog with Pynt! Explore source types, tailoring your API discovery for enhanced security.

Explore source categories in Pynt to tailor your API discovery and enhance security. Pynt allows you to categorize and manage different source types, such as scans, documentation, and gateways, providing a more structured and focused approach to your API security management. By organizing your sources into specific categories, you can easily navigate and prioritize your security efforts, ensuring that each aspect of your API environment is thoroughly monitored and protected. This feature helps you customize your API discovery process, making your security management more efficient and effective.

\
API source categories refer to the classification of **different types of sources** based on their characteristics or functionalities. In Pynt, these categories help organize and distinguish the various sources used for API discovery and security testing. Here are some common source categories in Pynt:

1. [API Gateway](/documentation/applications-view/manage-sources-for-api-discovery/source-categories/api-gateways)
2. [API Documentation](/documentation/applications-view/manage-sources-for-api-discovery/source-categories/api-documentation)
3. [Code Repository](/documentation/applications-view/manage-sources-for-api-discovery/source-categories/code-repository)
4. [Pynt API Security Testing](/documentation/applications-view/manage-sources-for-api-discovery/source-categories/testing-api-security-scans)

Each category serves a specific purpose in enhancing the API catalog and security posture within Pynt.




---

[Next Page](/documentation/llms-full.txt/1)

