API authentication attacks
SkillSecurityBreak API authentication: token handling, key leakage, weak session/JWT, and no-auth endpoints. Load on REST/GraphQL APIs using API keys, Bearer tokens, HMAC signing, or basic auth. Signals: `Authorization` headers, api_key params, tokens in URLs, /v1 vs /v2 auth drift.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the API authentication attacks skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/api/api-auth-attacks/SKILL.md and read by ahel’s review.
When it applies
An API authenticates requests via tokens/keys/sessions. Auth is the gate; weaknesses here open everything behind it.
Why it works
APIs sprawl (many endpoints, versions, clients) so authentication is applied inconsistently: some routes forgot it, tokens are long-lived or weakly signed, keys leak client-side, and error/timing differences enable enumeration and brute force.
Method
- No-auth endpoints: replay requests with the token removed; probe
/v1vs/v2,/internal,/debug, and undocumented routes (Swagger/OpenAPI) for missing auth. - Token weaknesses: JWT issues (→
web-auth-jwt: alg confusion, weak secret, none); long/ non-expiring tokens; predictable session ids; token accepted in URL (logged/leaked). - Key leakage: hunt keys in JS bundles, mobile apps, git (→
code-review-secrets-detection), and test their privilege/scope. - Brute/enumeration: username enumeration via login/reset differences; weak rate limits on
login/OTP (→
web-race-conditionsfor OTP windows). - Auth logic: password reset token predictability/leak, 2FA bypass, "remember me" tokens.
Gotchas
- Test every version and verb — the fix may exist only on the newest route.
- A leaked key must be live and privileged to matter — validate scope, don't over-collect.
- Rate-limit "bypass" via parallelism or header rotation is reportable on many programs.
Verify success
Authenticated access without valid credentials (no-auth route, forged/replayed token, or a live leaked key performing a privileged action).
References
OWASP API Security Top 10 (API2); PortSwigger auth labs.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
api-auth-attacks- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptsecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secretsowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)