course · api security

APIs run the internet. Learn to secure them properly.

36 hours · nine modules · task-based exam

A practical approach to agile and automation techniques in API security: hands-on, DevSecOps-first, and built for the way APIs are actually attacked.

APIs are most of the traffic, and most of the risk.

APIs now account for around 80% of total internet traffic, and that makes them one of the largest attack surfaces you own. CASP is for security professionals, offensive-security and red-team engineers, application-security engineers, developers and DevOps engineers. You'll want basic Linux and familiarity with the OWASP Top 10. Over 36 hours, 8 hours of video plus 28 hours of hands-on work across 40+ exercises, you learn to attack and defend APIs and bake that security into your pipeline. Comes with 60 days of lab access and 3 years of on-demand access.

DevSecOps runs through every module.

module 01

Introduction to API Security

How APIs are exposed, why they fail, and the shape of the modern API attack surface.

module 02

API Security Tools of the Trade

The tooling you'll use to test, intercept and harden APIs in practice.

module 03

Authentication Attacks & Defenses

OAuth 2.0 and 2.1, JWT handling, and the authentication flaws attackers rely on.

module 04

Authorization Attacks & Defenses

Broken object-level and function-level authorization, and RBAC/ABAC/ReBAC done right.

module 05

Input-Validation Threats & Defenses

Injection, mass assignment and the validation patterns that stop them.

module 06

OWASP API Top 10

Every entry worked through hands-on, with exploitation and mitigation.

module 07

API Security Defenses

Rate limiting, gateways, secrets and the controls that hold under load.

module 08

Implementing API Security Mechanisms

Put the controls in place across REST, GraphQL and SOAP.

module 09

API Security the DevSecOps Way

SCA, SAST and DAST in CI/CD, HashiCorp Vault, and continuous API assurance.

Technologies covered: OAuth 2.0 / 2.1 · JWT · RBAC / ABAC / ReBAC · REST / GraphQL / SOAP · SCA / SAST / DAST in CI/CD · HashiCorp Vault · OWASP ASVS.

Proven by solving real challenges.

0
Real challenges to solve
0h
To complete the exam
0%
Minimum score to pass
0h
To submit your report

The exam is task-oriented: five real challenges, six hours. Pass, and you hold the Certified API Security Professional (CASP) credential.

Authored by Practical DevSecOps.

CASP is a certification by Practical DevSecOps (Hysn Technologies Inc). Arxia offers and facilitates it, so the credential comes from a recognized security-training specialist and the training ties directly into how your team builds and ships.

Frequently asked

Authentication and authorization attacks and defenses, input-validation threats, the OWASP API Top 10, and how to build API security into a DevSecOps pipeline, all hands-on across nine modules.

36 hours total: about 8 hours of video plus 28 hours of hands-on work across 40+ exercises. It runs online, with 60 days of lab access and 3 years of on-demand access to the material.

It's task-oriented. You get five real challenges to solve in six hours, need at least 80% to pass, and have 24 hours to submit your report. Pass, and you hold the CASP credential.

Security professionals, offensive-security and red-team engineers, application-security engineers, developers and DevOps engineers. You'll want basic Linux and familiarity with the OWASP Top 10.

OAuth 2.0 and 2.1, JWT, RBAC/ABAC/ReBAC, REST, GraphQL and SOAP, SCA/SAST/DAST in CI/CD, HashiCorp Vault, and the OWASP ASVS.

pricing

Pricing depends on cohort size and delivery format. Ask us for current CASP pricing and the next available cohort, we'll get back to you within two business days.

Let's find your first win.

Tell us how your team works today and what's slowing it down. We'll point you to the right starting line. For most teams, that's a one-day AI Ignite workshop.

Enroll, or ask about the next cohort.

Tell us who's taking CASP and when you'd like to start. We'll confirm the next cohort, pricing and lab access.

Website arxia.global
HQ Cluj-Napoca, Romania
Offices Santiago, Chile · Kampala, Uganda

We reply within two business days. No spam, ever.

Thank you! We've received your message and will get back to you shortly.