Capital

Capital

c{api}tal is a vulnerable API security application designed for educational purposes created by the Checkmarx research team.

331GitHub
Description

c{api}tal is a vulnerable API security application designed for educational purposes created by the Checkmarx research team. The app is designed to provide users with an active driving ground to improve their API security skills. c{api}tal contains 10 API challenges that correspond to the top 10 OWASP API risks. The application is built using Python (FastAPI) as the back end and JavaScript (React) as the front end. You can use it after registering yourself. The main functions of c{api}tal include: - Provides 10 challenges based on the top 10 API risks of OWASP. - Use FastAPI to build the backend and React to build the front-end. - Provides a user interface for a blog site (similar to Medium). - Provides an OpenAPI3 API JSON specification file that can be imported into POSTMAN. - JWT-based token authentication (its life cycle can be adjusted in the application). Users can register, create and delete posts, create and delete comments, follow other users, etc. through c{api}tal. In addition, c{api}tal can also be used to hold API security CTF activities. The source code for the project is hosted on GitHub and follows the GNU Affero General Public License (AGPL-3.0). Development and contribution information for the project can be found on GitHub, and community members are welcome to submit questions or contribute code.

Screenshots
Screenshot 1
Screenshot 2
Mobile Screenshots
Mobile Screenshot 1
Mobile Screenshot 2
Mobile Screenshot 3
App Information
Version
0.0.1
Package Size
551.85 KB
Updated
October 10, 2025
Source Code
Checkmarx
Platform Support
PCMobile
Keywords
safe shooting range