API authentication attacks
SkillSecurityBreak API authentication: token handling, key leakage, weak session/JWT, and no-auth endpoints. Load on REST/GraphQL APIs using API keys, Bearer tokens, HMAC signing, or basic auth. Signals: `Authorization` headers, api_key params, tokens in URLs, /v1 vs /v2 auth drift.
Use API authentication attacks in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add API authentication attacks and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the API authentication attacks skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/api/api-auth-attacks/SKILL.md and read by Ahel’s review.
When it applies
An API authenticates requests via tokens/keys/sessions. Auth is the gate; weaknesses here open everything behind it.
Why it works
APIs sprawl (many endpoints, versions, clients) so authentication is applied inconsistently: some routes forgot it, tokens are long-lived or weakly signed, keys leak client-side, and error/timing differences enable enumeration and brute force.
Method
- No-auth endpoints: replay requests with the token removed; probe
/v1vs/v2,/internal,/debug, and undocumented routes (Swagger/OpenAPI) for missing auth. - Token weaknesses: JWT issues (→
web-auth-jwt: alg confusion, weak secret, none); long/ non-expiring tokens; predictable session ids; token accepted in URL (logged/leaked). - Key leakage: hunt keys in JS bundles, mobile apps, git (→
code-review-secrets-detection), and test their privilege/scope. - Brute/enumeration: username enumeration via login/reset differences; weak rate limits on
login/OTP (→
web-race-conditionsfor OTP windows). - Auth logic: password reset token predictability/leak, 2FA bypass, "remember me" tokens.
Gotchas
- Test every version and verb — the fix may exist only on the newest route.
- A leaked key must be live and privileged to matter — validate scope, don't over-collect.
- Rate-limit "bypass" via parallelism or header rotation is reportable on many programs.
Verify success
Authenticated access without valid credentials (no-auth route, forged/replayed token, or a live leaked key performing a privileged action).
References
OWASP API Security Top 10 (API2); PortSwigger auth labs.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
api-auth-attacks- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secretschecking-owasp-compliance
Skill · jeremylongshore
The pick for Web (OWASP)owasp-security
Skill · davila7
The pick for Web (OWASP)gws-shared
Skill · googleworkspace
More in Securitydefi-amm-security
Skill · affaan-m
More in Security