The current OpenAPI parsing and handling tools are not geared towards pentesting an API. We created Swagger-EZ to make getting up and running with API pentesting faster and less painful. The Github repository is here.
When auditing an API…
Chances are, if you’re developing a web application, you’ve probably integrated your app with other online apps. Maybe you’re using Google or Facebook as login options, or maybe your app is a data source for someone else’s app….