course · api security
APIs run the internet. Learn to secure them properly.
36 hours · nine modules · task-based exam
A practical approach to agile and automation techniques in API security: hands-on, DevSecOps-first, and built for the way APIs are actually attacked.
sec. 01 · who it's for
APIs are most of the traffic, and most of the risk.
APIs now account for around 80% of total internet traffic, and that makes them one of the largest attack surfaces you own. CASP is for security professionals, offensive-security and red-team engineers, application-security engineers, developers and DevOps engineers. You'll want basic Linux and familiarity with the OWASP Top 10. Over 36 hours, 8 hours of video plus 28 hours of hands-on work across 40+ exercises, you learn to attack and defend APIs and bake that security into your pipeline. Comes with 60 days of lab access and 3 years of on-demand access.
sec. 02 · syllabus
DevSecOps runs through every module.
Introduction to API Security
How APIs are exposed, why they fail, and the shape of the modern API attack surface.
API Security Tools of the Trade
The tooling you'll use to test, intercept and harden APIs in practice.
Authentication Attacks & Defenses
OAuth 2.0 and 2.1, JWT handling, and the authentication flaws attackers rely on.
Authorization Attacks & Defenses
Broken object-level and function-level authorization, and RBAC/ABAC/ReBAC done right.
Input-Validation Threats & Defenses
Injection, mass assignment and the validation patterns that stop them.
OWASP API Top 10
Every entry worked through hands-on, with exploitation and mitigation.
API Security Defenses
Rate limiting, gateways, secrets and the controls that hold under load.
Implementing API Security Mechanisms
Put the controls in place across REST, GraphQL and SOAP.
API Security the DevSecOps Way
SCA, SAST and DAST in CI/CD, HashiCorp Vault, and continuous API assurance.
Technologies covered: OAuth 2.0 / 2.1 · JWT · RBAC / ABAC / ReBAC · REST / GraphQL / SOAP · SCA / SAST / DAST in CI/CD · HashiCorp Vault · OWASP ASVS.
sec. 03 · certification & exam
Proven by solving real challenges.
The exam is task-oriented: five real challenges, six hours. Pass, and you hold the Certified API Security Professional (CASP) credential.
sec. 04 · delivered with
Authored by Practical DevSecOps.
CASP is a certification by Practical DevSecOps (Hysn Technologies Inc). Arxia offers and facilitates it, so the credential comes from a recognized security-training specialist and the training ties directly into how your team builds and ships.
sec. 05 · questions
Frequently asked
Authentication and authorization attacks and defenses, input-validation threats, the OWASP API Top 10, and how to build API security into a DevSecOps pipeline, all hands-on across nine modules.
36 hours total: about 8 hours of video plus 28 hours of hands-on work across 40+ exercises. It runs online, with 60 days of lab access and 3 years of on-demand access to the material.
It's task-oriented. You get five real challenges to solve in six hours, need at least 80% to pass, and have 24 hours to submit your report. Pass, and you hold the CASP credential.
Security professionals, offensive-security and red-team engineers, application-security engineers, developers and DevOps engineers. You'll want basic Linux and familiarity with the OWASP Top 10.
OAuth 2.0 and 2.1, JWT, RBAC/ABAC/ReBAC, REST, GraphQL and SOAP, SCA/SAST/DAST in CI/CD, HashiCorp Vault, and the OWASP ASVS.
Pricing depends on cohort size and delivery format. Ask us for current CASP pricing and the next available cohort, we'll get back to you within two business days.
next step
Let's find your first win.
Tell us how your team works today and what's slowing it down. We'll point you to the right starting line. For most teams, that's a one-day AI Ignite workshop.
enroll
Enroll, or ask about the next cohort.
Tell us who's taking CASP and when you'd like to start. We'll confirm the next cohort, pricing and lab access.