{
    "archive_path": "archive/1736015745.600181",
    "base_url": "github.com/shieldfy/API-Security-Checklist",
    "basename": "API-Security-Checklist",
    "bookmarked_date": "2025-01-04 18:35",
    "canonical": {
        "archive_org_path": "https://web.archive.org/web/github.com/shieldfy/API-Security-Checklist",
        "dom_path": "output.html",
        "favicon_path": "favicon.ico",
        "git_path": "git/",
        "google_favicon_path": "https://www.google.com/s2/favicons?domain=github.com",
        "headers_path": "headers.json",
        "htmltotext_path": "htmltotext.txt",
        "index_path": "index.html",
        "media_path": "media/",
        "mercury_path": "mercury/content.html",
        "pdf_path": "output.pdf",
        "readability_path": "readability/content.html",
        "screenshot_path": "screenshot.png",
        "singlefile_path": "singlefile.html",
        "warc_path": "warc/",
        "wget_path": null
    },
    "domain": "github.com",
    "downloaded_at": "2025-01-04T18:37:03.569774+00:00",
    "downloaded_datestr": "2025-01-04 18:37",
    "extension": "",
    "hash": "14H12CVJ90Y7956R99A2",
    "history": {
        "archive_org": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--head",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://web.archive.org/save/https://github.com/shieldfy/API-Security-Checklist"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2025-01-04T18:37:54.490503+00:00",
                "index_texts": null,
                "output": "ArchiveError: Failed to find \"content-location\" URL header in Archive.org response.",
                "pwd": "/data/archive/1736015745.600181",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:37:53.062286+00:00",
                "status": "failed"
            }
        ],
        "dom": [
            {
                "cmd": [
                    "/usr/bin/chromium-browser",
                    "--proxy-server=socks5://tor-socks-proxy:9150",
                    "--disable-features=DarkMode",
                    "--run-all-compositor-stages-before-draw",
                    "--hide-scrollbars",
                    "--autoplay-policy=no-user-gesture-required",
                    "--no-first-run",
                    "--use-fake-ui-for-media-stream",
                    "--use-fake-device-for-media-stream",
                    "--simulate-outdated-no-au='Tue, 31 Dec 2099 23:59:59 GMT'",
                    "--headless=new",
                    "--no-sandbox",
                    "--no-zygote",
                    "--disable-dev-shm-usage",
                    "--disable-software-rasterizer",
                    "--disable-sync",
                    "--window-size=1440,2000",
                    "--user-agent=Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "--user-data-dir=/data/personas/Default/chrome_profile",
                    "--profile-directory=Default",
                    "--dump-dom",
                    "https://github.com/shieldfy/API-Security-Checklist"
                ],
                "cmd_version": "131.0.6778",
                "end_ts": "2025-01-04T18:37:21.282056+00:00",
                "index_texts": null,
                "output": "output.html",
                "pwd": "/data/archive/1736015745.600181",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:37:08.012071+00:00",
                "status": "succeeded"
            }
        ],
        "favicon": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--max-time",
                    "60",
                    "--output",
                    "favicon.ico",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://www.google.com/s2/favicons?domain=github.com"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2025-01-04T18:37:07.331866+00:00",
                "index_texts": null,
                "output": "favicon.ico",
                "pwd": "/data/archive/1736015745.600181",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:37:03.656506+00:00",
                "status": "succeeded"
            }
        ],
        "git": [],
        "headers": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--head",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://github.com/shieldfy/API-Security-Checklist"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2025-01-04T18:37:07.916701+00:00",
                "index_texts": null,
                "output": "headers.json",
                "pwd": "/data/archive/1736015745.600181",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:37:07.377273+00:00",
                "status": "succeeded"
            }
        ],
        "htmltotext": [
            {
                "cmd": [
                    "(internal) archivebox.extractors.htmltotext",
                    "./{singlefile,dom}.html"
                ],
                "cmd_version": "0.8.5rc51",
                "end_ts": "2025-01-04T18:37:46.250038+00:00",
                "index_texts": [
                    "(https://github.githubassets.com) (https://avatars.githubusercontent.com) (https://github-cloud.s3.amazonaws.com) (https://user-images.githubusercontent.com/) (https://github.githubassets.com) (https://avatars.githubusercontent.com) (https://github.githubassets.com/assets/light-0cfd1fd8509e.css) (https://github.githubassets.com/assets/dark-d782f59290e2.css) (https://github.githubassets.com/assets/primer-primitives-953961b66e63.css) (https://github.githubassets.com/assets/primer-4430d3c2c150.css) (https://github.githubassets.com/assets/global-47b8b2ca21ae.css) (https://github.githubassets.com/assets/github-e72829f5538b.css) (https://github.githubassets.com/assets/repository-d031bcc14e1b.css) (https://github.githubassets.com/assets/code-9e1913b328be.css) (https://github.githubassets.com/assets/primer-react.797c8ec006b327590422.module.css) (https://github.githubassets.com/assets/notifications-subscriptions-menu.1bcff9205c241e99cff2.module.css) (https://github.githubassets.com/assets/primer-react.797c8ec006b327590422.module.css) (https://github.githubassets.com/assets/notifications-subscriptions-menu.1bcff9205c241e99cff2.module.css) GitHub - shieldfy/API-Security-Checklist: Checklist of the most important security countermeasures when designing, testing, and releasing your API (repo_source) (https://github.githubassets.com/) (/opensearch.xml) (GitHub) (https://github.com/fluidicon.png) (GitHub) (https://github.com/shieldfy/API-Security-Checklist) (https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg) (https://github.githubassets.com/favicons/favicon.png) (https://github.githubassets.com/favicons/favicon.svg) (/manifest.json)  Skip to content   (https://github.githubassets.com/assets/primer-react.797c8ec006b327590422.module.css)    Navigation Menu Toggle navigation         (/)    (/login?return_to=https%3A%2F%2Fgithub.com%2Fshieldfy%2FAPI-Security-Checklist) Sign in    Product    (https://github.com/features/copilot)    GitHub Copilot Write better code with AI    (https://github.com/features/security)    Security Find and fix vulnerabilities    (https://github.com/features/actions)   Actions Automate any workflow    (https://github.com/features/codespaces)    Codespaces Instant dev environments    (https://github.com/features/issues)   Issues Plan and track work    (https://github.com/features/code-review)    Code Review Manage code changes    (https://github.com/features/discussions)    Discussions Collaborate outside of code    (https://github.com/features/code-search)    Code Search Find more, search less       Explore (https://github.com/features) All features   (https://docs.github.com) Documentation     (https://skills.github.com) GitHub Skills     (https://github.blog) Blog          Solutions    By company size (https://github.com/enterprise) Enterprises   (https://github.com/team) Small and medium teams   (https://github.com/enterprise/startups) Startups     By use case (/solutions/use-case/devsecops) DevSecOps   (/solutions/use-case/devops) DevOps   (/solutions/use-case/ci-cd) CI/CD   (/solutions/use-case) View all use cases      By industry (/solutions/industry/healthcare) Healthcare   (/solutions/industry/financial-services) Financial services   (/solutions/industry/manufacturing) Manufacturing   (/solutions/industry/government) Government   (/solutions/industry) View all industries      (/solutions) View all solutions       Resources    Topics (/resources/articles/ai) AI   (/resources/articles/devops) DevOps   (/resources/articles/security) Security   (/resources/articles/software-development) Software Development   (/resources/articles) View all      Explore (https://resources.github.com/learn/pathways) Learning Pathways     (https://resources.github.com) White papers, Ebooks, Webinars     (https://github.com/customer-stories) Customer Stories   (https://partner.github.com) Partners     (https://github.com/solutions/executive-insights) Executive Insights        Open Source    (/sponsors) GitHub Sponsors Fund open source developers      (https://github.com/readme) The ReadME Project GitHub community articles      Repositories (https://github.com/topics) Topics   (https://github.com/trending) Trending   (https://github.com/collections) Collections        Enterprise    (/enterprise)     Enterprise platform AI-powered developer platform      Available add-ons (https://github.com/enterprise/advanced-security)    Advanced Security Enterprise-grade security features    (/features/copilot#enterprise)    GitHub Copilot Enterprise-grade AI features    (/premium-support)    Premium Support Enterprise-grade 24/7 support         (https://github.com/pricing) Pricing    (Search or jump to...)    Search or jump to...      Search code, repositories, users, issues, pull requests... Search        ()   Clear                (https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax) Search syntax tips          Provide feedback         (KDXjBwEw/jl4pllYoneb5ZSpY5YAaXTumEda/ObUgMPqln0+3D/SSoQKgJVrb+A1ShjMXlCf15uTD0vk/i9OLw==) We read every piece of feedback, and take your input very seriously.  Include my email address so I can be contacted    Cancel  Submit feedback     Saved searches  Use saved searches to filter your results more quickly         (7BzrioaDDXA7o+BM/hA3cmLyCdxzvJWBjMUF5kCUdwpwM9dgMhBIdcvjN7jqUqfcejRK2jBkn0x1+qsz0uvBNQ==)  Name (github-ruby) (E1GDi0+aIDIAglR51AKu3qHah7X1KgOdQOV1aiyNuirVvcCURNwRS9lO9IKJB+w/oA/ynNTx8VCllTX7KnWXpQ==)   Query ((repo:mona/a OR repo:mona/b) AND lang:python)  To see all available qualifiers, see our (https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax) documentation .        Cancel  Create saved search        (/login?return_to=https%3A%2F%2Fgithub.com%2Fshieldfy%2FAPI-Security-Checklist) Sign in   (/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E&source=header-repo&source_repo=shieldfy%2FAPI-Security-Checklist) Sign up  Reseting focus        You signed in with another tab or window. () Reload to refresh your session. You signed out in another tab or window. () Reload to refresh your session. You switched accounts on another tab or window. () Reload to refresh your session.    Dismiss alert       (/shieldfy) shieldfy   / (/shieldfy/API-Security-Checklist) API-Security-Checklist   Public   (/login?return_to=%2Fshieldfy%2FAPI-Security-Checklist)   Notifications  You must be signed in to change notification settings  (/login?return_to=%2Fshieldfy%2FAPI-Security-Checklist)   Fork (2,608) 2.6k   (/login?return_to=%2Fshieldfy%2FAPI-Security-Checklist)   Star  (22,552) 22.6k       Checklist of the most important security countermeasures when designing, testing, and releasing your API  License (/shieldfy/API-Security-Checklist/blob/master/LICENSE)   MIT license   (/shieldfy/API-Security-Checklist/stargazers)   22.6k stars  (/shieldfy/API-Security-Checklist/forks)   2.6k forks  (/shieldfy/API-Security-Checklist/branches)   Branches  (/shieldfy/API-Security-Checklist/tags)   Tags  (/shieldfy/API-Security-Checklist/activity)   Activity   (/login?return_to=%2Fshieldfy%2FAPI-Security-Checklist)   Star     (/login?return_to=%2Fshieldfy%2FAPI-Security-Checklist)   Notifications  You must be signed in to change notification settings      (/shieldfy/API-Security-Checklist)   Code (Not available)    (/shieldfy/API-Security-Checklist/issues)    Issues (12) 12   (/shieldfy/API-Security-Checklist/pulls)   Pull requests (1) 1   (/shieldfy/API-Security-Checklist/actions)   Actions (Not available)    (/shieldfy/API-Security-Checklist/projects)   Projects (0) 0   (/shieldfy/API-Security-Checklist/security)   Security   (/shieldfy/API-Security-Checklist/pulse)   Insights (Not available)        Additional navigation options (/shieldfy/API-Security-Checklist)    Code    (/shieldfy/API-Security-Checklist/issues)     Issues    (/shieldfy/API-Security-Checklist/pulls)    Pull requests    (/shieldfy/API-Security-Checklist/actions)    Actions    (/shieldfy/API-Security-Checklist/projects)    Projects    (/shieldfy/API-Security-Checklist/security)    Security    (/shieldfy/API-Security-Checklist/pulse)    Insights               shieldfy/API-Security-Checklist (https://github.githubassets.com/assets/primer-react.797c8ec006b327590422.module.css) (https://github.githubassets.com/assets/repos-overview.9cc263aa0716ce801059.module.css)      master           (/shieldfy/API-Security-Checklist/branches)    1  Branch    (/shieldfy/API-Security-Checklist/tags)    0  Tags     (/shieldfy/API-Security-Checklist/branches)    (/shieldfy/API-Security-Checklist/tags)       Go to file          Code              Folders and files Name  Name  (Last commit message) Last commit message   (Last commit date) Last commit date     Latest commit (/Maikuolan) (Maikuolan)  (/shieldfy/API-Security-Checklist/commits?author=Maikuolan) Maikuolan    (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024   (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) d4a8730 \u00b7 (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024   History (/shieldfy/API-Security-Checklist/commits/master/)    359 Commits        (/shieldfy/API-Security-Checklist/commits/master/)               (CONTRIBUTING.md) (/shieldfy/API-Security-Checklist/blob/master/CONTRIBUTING.md) CONTRIBUTING.md        (CONTRIBUTING.md) (/shieldfy/API-Security-Checklist/blob/master/CONTRIBUTING.md) CONTRIBUTING.md      (add languages list link to CONTRIBUTING.md file) (/shieldfy/API-Security-Checklist/commit/a9527471fb3062c92634820b95f18bbfaad943ff) add languages list link to CONTRIBUTING.md file    (Jul 13, 2017, 9:10 AM UTC) Jul 13, 2017      (LICENSE) (/shieldfy/API-Security-Checklist/blob/master/LICENSE) LICENSE        (LICENSE) (/shieldfy/API-Security-Checklist/blob/master/LICENSE) LICENSE      (Initial commit) (/shieldfy/API-Security-Checklist/commit/6ebec2699116486b238f8200341043cad5f8feab) Initial commit    (Jul 8, 2017, 8:01 PM UTC) Jul 8, 2017      (README-ar.md) (/shieldfy/API-Security-Checklist/blob/master/README-ar.md) README-ar.md        (README-ar.md) (/shieldfy/API-Security-Checklist/blob/master/README-ar.md) README-ar.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-az.md) (/shieldfy/API-Security-Checklist/blob/master/README-az.md) README-az.md        (README-az.md) (/shieldfy/API-Security-Checklist/blob/master/README-az.md) README-az.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-bg.md) (/shieldfy/API-Security-Checklist/blob/master/README-bg.md) README-bg.md        (README-bg.md) (/shieldfy/API-Security-Checklist/blob/master/README-bg.md) README-bg.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-bn.md) (/shieldfy/API-Security-Checklist/blob/master/README-bn.md) README-bn.md        (README-bn.md) (/shieldfy/API-Security-Checklist/blob/master/README-bn.md) README-bn.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-ca.md) (/shieldfy/API-Security-Checklist/blob/master/README-ca.md) README-ca.md        (README-ca.md) (/shieldfy/API-Security-Checklist/blob/master/README-ca.md) README-ca.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-cs.md) (/shieldfy/API-Security-Checklist/blob/master/README-cs.md) README-cs.md        (README-cs.md) (/shieldfy/API-Security-Checklist/blob/master/README-cs.md) README-cs.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-de.md) (/shieldfy/API-Security-Checklist/blob/master/README-de.md) README-de.md        (README-de.md) (/shieldfy/API-Security-Checklist/blob/master/README-de.md) README-de.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-el.md) (/shieldfy/API-Security-Checklist/blob/master/README-el.md) README-el.md        (README-el.md) (/shieldfy/API-Security-Checklist/blob/master/README-el.md) README-el.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-es.md) (/shieldfy/API-Security-Checklist/blob/master/README-es.md) README-es.md        (README-es.md) (/shieldfy/API-Security-Checklist/blob/master/README-es.md) README-es.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-fa.md) (/shieldfy/API-Security-Checklist/blob/master/README-fa.md) README-fa.md        (README-fa.md) (/shieldfy/API-Security-Checklist/blob/master/README-fa.md) README-fa.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-fr.md) (/shieldfy/API-Security-Checklist/blob/master/README-fr.md) README-fr.md        (README-fr.md) (/shieldfy/API-Security-Checklist/blob/master/README-fr.md) README-fr.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-hi.md) (/shieldfy/API-Security-Checklist/blob/master/README-hi.md) README-hi.md        (README-hi.md) (/shieldfy/API-Security-Checklist/blob/master/README-hi.md) README-hi.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-id.md) (/shieldfy/API-Security-Checklist/blob/master/README-id.md) README-id.md        (README-id.md) (/shieldfy/API-Security-Checklist/blob/master/README-id.md) README-id.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-it.md) (/shieldfy/API-Security-Checklist/blob/master/README-it.md) README-it.md        (README-it.md) (/shieldfy/API-Security-Checklist/blob/master/README-it.md) README-it.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-ja.md) (/shieldfy/API-Security-Checklist/blob/master/README-ja.md) README-ja.md        (README-ja.md) (/shieldfy/API-Security-Checklist/blob/master/README-ja.md) README-ja.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-ko.md) (/shieldfy/API-Security-Checklist/blob/master/README-ko.md) README-ko.md        (README-ko.md) (/shieldfy/API-Security-Checklist/blob/master/README-ko.md) README-ko.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-lo.md) (/shieldfy/API-Security-Checklist/blob/master/README-lo.md) README-lo.md        (README-lo.md) (/shieldfy/API-Security-Checklist/blob/master/README-lo.md) README-lo.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-mk.md) (/shieldfy/API-Security-Checklist/blob/master/README-mk.md) README-mk.md        (README-mk.md) (/shieldfy/API-Security-Checklist/blob/master/README-mk.md) README-mk.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-ml.md) (/shieldfy/API-Security-Checklist/blob/master/README-ml.md) README-ml.md        (README-ml.md) (/shieldfy/API-Security-Checklist/blob/master/README-ml.md) README-ml.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-mn.md) (/shieldfy/API-Security-Checklist/blob/master/README-mn.md) README-mn.md        (README-mn.md) (/shieldfy/API-Security-Checklist/blob/master/README-mn.md) README-mn.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-nl.md) (/shieldfy/API-Security-Checklist/blob/master/README-nl.md) README-nl.md        (README-nl.md) (/shieldfy/API-Security-Checklist/blob/master/README-nl.md) README-nl.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-pl.md) (/shieldfy/API-Security-Checklist/blob/master/README-pl.md) README-pl.md        (README-pl.md) (/shieldfy/API-Security-Checklist/blob/master/README-pl.md) README-pl.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-pt_BR.md) (/shieldfy/API-Security-Checklist/blob/master/README-pt_BR.md) README-pt_BR.md        (README-pt_BR.md) (/shieldfy/API-Security-Checklist/blob/master/README-pt_BR.md) README-pt_BR.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-ru.md) (/shieldfy/API-Security-Checklist/blob/master/README-ru.md) README-ru.md        (README-ru.md) (/shieldfy/API-Security-Checklist/blob/master/README-ru.md) README-ru.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-th.md) (/shieldfy/API-Security-Checklist/blob/master/README-th.md) README-th.md        (README-th.md) (/shieldfy/API-Security-Checklist/blob/master/README-th.md) README-th.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-tr.md) (/shieldfy/API-Security-Checklist/blob/master/README-tr.md) README-tr.md        (README-tr.md) (/shieldfy/API-Security-Checklist/blob/master/README-tr.md) README-tr.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-tw.md) (/shieldfy/API-Security-Checklist/blob/master/README-tw.md) README-tw.md        (README-tw.md) (/shieldfy/API-Security-Checklist/blob/master/README-tw.md) README-tw.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-uk.md) (/shieldfy/API-Security-Checklist/blob/master/README-uk.md) README-uk.md        (README-uk.md) (/shieldfy/API-Security-Checklist/blob/master/README-uk.md) README-uk.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-vi.md) (/shieldfy/API-Security-Checklist/blob/master/README-vi.md) README-vi.md        (README-vi.md) (/shieldfy/API-Security-Checklist/blob/master/README-vi.md) README-vi.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README-zh.md) (/shieldfy/API-Security-Checklist/blob/master/README-zh.md) README-zh.md        (README-zh.md) (/shieldfy/API-Security-Checklist/blob/master/README-zh.md) README-zh.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024      (README.md) (/shieldfy/API-Security-Checklist/blob/master/README.md) README.md        (README.md) (/shieldfy/API-Security-Checklist/blob/master/README.md) README.md      (Sync.) (/shieldfy/API-Security-Checklist/commit/d4a873093b3ff63b6bd7d156a1e650bf0199f9fa) Sync.    (Nov 22, 2024, 2:52 AM UTC) Nov 22, 2024    View all files       Repository files navigation    README      MIT license         (/shieldfy/API-Security-Checklist/blob/master/README-tw.md) \u7e41\u4e2d\u7248 | (/shieldfy/API-Security-Checklist/blob/master/README-zh.md) \u7b80\u4e2d\u7248 | (/shieldfy/API-Security-Checklist/blob/master/README-ar.md) \u0627\u0644\u0639\u0631\u0628\u064a\u0629 | (/shieldfy/API-Security-Checklist/blob/master/README-az.md) Az\u0259rbaycan | (/shieldfy/API-Security-Checklist/blob/master/README-bg.md) \u0411\u044a\u043b\u0433\u0430\u0440\u0441\u043a\u0438 | (/shieldfy/API-Security-Checklist/blob/master/README-bn.md) \u09ac\u09be\u0982\u09b2\u09be | (/shieldfy/API-Security-Checklist/blob/master/README-ca.md) Catal\u00e0 | (/shieldfy/API-Security-Checklist/blob/master/README-cs.md) \u010ce\u0161tina | (/shieldfy/API-Security-Checklist/blob/master/README-de.md) Deutsch | (/shieldfy/API-Security-Checklist/blob/master/README-el.md) \u0395\u03bb\u03bb\u03b7\u03bd\u03b9\u03ba\u03ac | (/shieldfy/API-Security-Checklist/blob/master/README-es.md) Espa\u00f1ol | (/shieldfy/API-Security-Checklist/blob/master/README-fa.md) \u0641\u0627\u0631\u0633\u06cc | (/shieldfy/API-Security-Checklist/blob/master/README-fr.md) Fran\u00e7ais | (/shieldfy/API-Security-Checklist/blob/master/README-hi.md) \u0939\u093f\u0902\u0926\u0940 | (/shieldfy/API-Security-Checklist/blob/master/README-id.md) Indonesia | (/shieldfy/API-Security-Checklist/blob/master/README-it.md) Italiano | (/shieldfy/API-Security-Checklist/blob/master/README-ja.md) \u65e5\u672c\u8a9e | (/shieldfy/API-Security-Checklist/blob/master/README-ko.md) \ud55c\uad6d\uc5b4 | (/shieldfy/API-Security-Checklist/blob/master/README-lo.md) \u0e9e\u0eb2\u0eaa\u0eb2\u0ea5\u0eb2\u0ea7 | (/shieldfy/API-Security-Checklist/blob/master/README-mk.md) \u041c\u0430\u043a\u0435\u0434\u043e\u043d\u0441\u043a\u0438 | (/shieldfy/API-Security-Checklist/blob/master/README-ml.md) \u0d2e\u0d32\u0d2f\u0d3e\u0d33\u0d02 | (/shieldfy/API-Security-Checklist/blob/master/README-mn.md) \u041c\u043e\u043d\u0433\u043e\u043b | (/shieldfy/API-Security-Checklist/blob/master/README-nl.md) Nederlands | (/shieldfy/API-Security-Checklist/blob/master/README-pl.md) Polski | (/shieldfy/API-Security-Checklist/blob/master/README-pt_BR.md) Portugu\u00eas (Brasil) | (/shieldfy/API-Security-Checklist/blob/master/README-ru.md) \u0420\u0443\u0441\u0441\u043a\u0438\u0439 | (/shieldfy/API-Security-Checklist/blob/master/README-th.md) \u0e44\u0e17\u0e22 | (/shieldfy/API-Security-Checklist/blob/master/README-tr.md) T\u00fcrk\u00e7e | (/shieldfy/API-Security-Checklist/blob/master/README-uk.md) \u0423\u043a\u0440\u0430\u0457\u043d\u0441\u044c\u043a\u0430 | (/shieldfy/API-Security-Checklist/blob/master/README-vi.md) Ti\u1ebfng Vi\u1ec7t  API Security Checklist     Checklist of the most important security countermeasures when designing, testing, and releasing your API. Authentication     Don't use Basic Auth . Use standard authentication instead (e.g., (https://jwt.io/) JWT ). Don't reinvent the wheel in Authentication , token generation , password storage . Use the standards. Use Max Retry and jail features in Login. Use encryption on all sensitive data.  JWT (JSON Web Token)     Use a random complicated key (JWT Secret ) to make brute forcing the token very hard. Don't extract the algorithm from the header. Force the algorithm in the backend (HS256 or RS256 ). Make token expiration (TTL , RTTL ) as short as possible. Don't store sensitive data in the JWT payload, it can be decoded (https://jwt.io/#debugger-io) easily . Avoid storing too much data. JWT is usually shared in headers and they have a size limit.  Access     Limit requests (Throttling) to avoid DDoS / brute-force attacks. Use HTTPS on server side with TLS 1.2+ and secure ciphers to avoid MITM (Man in the Middle Attack). Use HSTS header with SSL to avoid SSL Strip attacks. Turn off directory listings. For private APIs, allow access only from safelisted IPs/hosts.  Authorization     OAuth     Always validate redirect_uri server-side to allow only safelisted URLs. Always try to exchange for code and not tokens (don't allow response_type=token ). Use state parameter with a random hash to prevent CSRF on the OAuth authorization process. Define the default scope, and validate scope parameters for each application.  Input     Use the proper HTTP method according to the operation: GET (read) , POST (create) , PUT/PATCH (replace/update) , and DELETE (to delete a record) , and respond with 405 Method Not Allowed if the requested method isn't appropriate for the requested resource. Validate content-type on request Accept header (Content Negotiation) to allow only your supported format (e.g., application/xml , application/json , etc.) and respond with 406 Not Acceptable response if not matched. Validate content-type of posted data as you accept (e.g., application/x-www-form-urlencoded , multipart/form-data , application/json , etc.). Validate user input to avoid common vulnerabilities (e.g., XSS , SQL-Injection , Remote Code Execution , etc.). Don't use any sensitive data (credentials , Passwords , security tokens , or API keys ) in the URL, but use standard Authorization header. Use only server-side encryption. Use an API Gateway service to enable caching, Rate Limit policies (e.g., Quota , Spike Arrest , or Concurrent Rate Limit ) and deploy APIs resources dynamically.  Processing     Check if all the endpoints are protected behind authentication to avoid broken authentication process. User own resource ID should be avoided. Use /me/orders instead of /user/654321/orders . Don't auto-increment IDs. Use UUID instead. If you are parsing XML data, make sure entity parsing is not enabled to avoid XXE (XML external entity attack). If you are parsing XML, YAML or any other language with anchors and refs, make sure entity expansion is not enabled to avoid Billion Laughs/XML bomb via exponential entity expansion attack. Use a CDN for file uploads. If you are dealing with huge amount of data, use Workers and Queues to process as much as possible in background and return response fast to avoid HTTP Blocking. Do not forget to turn the DEBUG mode OFF. Use non-executable stacks when available.  Output     Send X-Content-Type-Options: nosniff header. Send X-Frame-Options: deny header. Send Content-Security-Policy: default-src 'none' header. Remove fingerprinting headers - X-Powered-By , Server , X-AspNet-Version , etc. Force content-type for your response. If you return application/json , then your content-type response is application/json . Don't return sensitive data like credentials , passwords , or security tokens . Return the proper status code according to the operation completed. (e.g., 200 OK , 400 Bad Request , 401 Unauthorized , 405 Method Not Allowed , etc.).  CI & CD     Audit your design and implementation with unit/integration tests coverage. Use a code review process and disregard self-approval. Ensure that all components of your services are statically scanned by AV software before pushing to production, including vendor libraries and other dependencies. Continuously run security tests (static/dynamic analysis) on your code. Check your dependencies (both software and OS) for known vulnerabilities. Design a rollback solution for deployments.  Monitoring     Use centralized logins for all services and components. Use agents to monitor all traffic, errors, requests, and responses. Use alerts for SMS, Slack, Email, Telegram, Kibana, Cloudwatch, etc. Ensure that you aren't logging any sensitive data like credit cards, passwords, PINs, etc. Use an IDS and/or IPS system to monitor your API requests and instances.  See also:     (https://github.com/yosriady/api-development-tools) yosriady/api-development-tools - A collection of useful resources for building RESTful HTTP+JSON APIs.  Contribution     Feel free to contribute by forking this repository, making some changes, and submitting pull requests. For any questions drop us an email at team@shieldfy.io .         (2S0VBSDw3bJvNqUlXH0IzO9O12ZBrNUyGGykedKZTzCK9p5PzsbfHImw7uplIg527YiAi2pwpnnCZAWAwJjxTw==)  About Checklist of the most important security countermeasures when designing, testing, and releasing your API  Topics (/topics/api) (Topic: api) api  (/topics/security) (Topic: security) security  (/topics/jwt) (Topic: jwt) jwt  (/topics/oauth2) (Topic: oauth2) oauth2    Resources   Readme   License   MIT license    (/shieldfy/API-Security-Checklist/activity)   Activity   (/shieldfy/API-Security-Checklist/custom-properties)   Custom properties   Stars (/shieldfy/API-Security-Checklist/stargazers)   22.6k stars  Watchers (/shieldfy/API-Security-Checklist/watchers)   542 watching  Forks (/shieldfy/API-Security-Checklist/forks)   2.6k forks  (/contact/report-content?content_url=https%3A%2F%2Fgithub.com%2Fshieldfy%2FAPI-Security-Checklist&report=shieldfy+%28user%29) Report repository      (/shieldfy/API-Security-Checklist/releases) Releases  No releases published   (/orgs/shieldfy/packages?repo_name=API-Security-Checklist) Packages (0) 0   No packages published       (/shieldfy/API-Security-Checklist/graphs/contributors) Contributors (89) 89   (https://github.com/Maikuolan) (@Maikuolan)   (https://github.com/netcode) (@netcode)   (https://github.com/7snovic) (@7snovic)   (https://github.com/khemso) (@khemso)   (https://github.com/pilotpirxie) (@pilotpirxie)   (https://github.com/filhocodes) (@filhocodes)   (https://github.com/umutphp) (@umutphp)   (https://github.com/Ehliman) (@Ehliman)   (https://github.com/msfidelis) (@msfidelis)   (https://github.com/TheBrown) (@TheBrown)   (https://github.com/tsybenko) (@tsybenko)   (https://github.com/zerbaliy3v) (@zerbaliy3v)   (https://github.com/iogi) (@iogi)   (https://github.com/flibustier) (@flibustier)    (/shieldfy/API-Security-Checklist/graphs/contributors) + 75 contributors              Footer (GitHub) (https://github.com)    \u00a9 2025 GitHub,\u00a0Inc.   Footer navigation (https://docs.github.com/site-policy/github-terms/github-terms-of-service) Terms  (https://docs.github.com/site-policy/privacy-policies/github-privacy-statement) Privacy  (https://github.com/security) Security  (https://www.githubstatus.com/) Status  (https://docs.github.com/) Docs  (https://support.github.com?tags=dotcom-footer) Contact  Manage cookies    Do not share my personal information              You can\u2019t perform that action at this time.         "
                ],
                "output": "htmltotext.txt",
                "pwd": "/data/archive/1736015745.600181",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:37:46.000161+00:00",
                "status": "succeeded"
            }
        ],
        "media": [
            {
                "cmd": [
                    "/usr/local/bin/yt-dlp",
                    "--restrict-filenames",
                    "--trim-filenames",
                    "128",
                    "--write-description",
                    "--write-info-json",
                    "--write-annotations",
                    "--write-thumbnail",
                    "--no-call-home",
                    "--write-sub",
                    "--write-auto-subs",
                    "--convert-subs=srt",
                    "--yes-playlist",
                    "--continue",
                    "--no-abort-on-error",
                    "--ignore-errors",
                    "--geo-bypass",
                    "--add-metadata",
                    "--format=(bv*+ba/b)[filesize<=750m][filesize_approx<=?750m]/(bv*+ba/b)",
                    "--skip-download",
                    "--cache-dir=/data/yt-dlp-cache/",
                    "--cookies=/data/yt-dlp-cache/cookies.txt",
                    "--proxy=socks5://tor-socks-proxy:9150",
                    "--no-playlist",
                    "https://github.com/shieldfy/API-Security-Checklist"
                ],
                "cmd_version": "2024.10.7",
                "end_ts": "2025-01-04T18:37:53.018497+00:00",
                "index_texts": [],
                "output": "media/",
                "pwd": "/data/archive/1736015745.600181",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:37:46.449168+00:00",
                "status": "succeeded"
            }
        ],
        "mercury": [
            {
                "cmd": [
                    "/home/archivebox/.npm/bin/postlight-parser",
                    "https://github.com/shieldfy/API-Security-Checklist"
                ],
                "cmd_version": "2.2.3",
                "end_ts": "2025-01-04T18:37:45.960670+00:00",
                "index_texts": null,
                "output": "mercury/",
                "pwd": "/data/archive/1736015745.600181",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:37:35.885962+00:00",
                "status": "succeeded"
            }
        ],
        "pdf": [],
        "readability": [
            {
                "cmd": [
                    "/home/archivebox/.npm/bin/readability-extractor",
                    "/tmp/tmpau1gnl91",
                    "https://github.com/shieldfy/API-Security-Checklist"
                ],
                "cmd_version": "0.0.11",
                "end_ts": "2025-01-04T18:37:35.795702+00:00",
                "index_texts": [
                    "\u7e41\u4e2d\u7248 | \u7b80\u4e2d\u7248 | \u0627\u0644\u0639\u0631\u0628\u064a\u0629 | Az\u0259rbaycan | \u0411\u044a\u043b\u0433\u0430\u0440\u0441\u043a\u0438 | \u09ac\u09be\u0982\u09b2\u09be | Catal\u00e0 | \u010ce\u0161tina | Deutsch | \u0395\u03bb\u03bb\u03b7\u03bd\u03b9\u03ba\u03ac | Espa\u00f1ol | \u0641\u0627\u0631\u0633\u06cc | Fran\u00e7ais | \u0939\u093f\u0902\u0926\u0940 | Indonesia | Italiano | \u65e5\u672c\u8a9e | \ud55c\uad6d\uc5b4 | \u0e9e\u0eb2\u0eaa\u0eb2\u0ea5\u0eb2\u0ea7 | \u041c\u0430\u043a\u0435\u0434\u043e\u043d\u0441\u043a\u0438 | \u0d2e\u0d32\u0d2f\u0d3e\u0d33\u0d02 | \u041c\u043e\u043d\u0433\u043e\u043b | Nederlands | Polski | Portugu\u00eas (Brasil) | \u0420\u0443\u0441\u0441\u043a\u0438\u0439 | \u0e44\u0e17\u0e22 | T\u00fcrk\u00e7e | \u0423\u043a\u0440\u0430\u0457\u043d\u0441\u044c\u043a\u0430 | Ti\u1ebfng Vi\u1ec7t\nAPI Security Checklist\nChecklist of the most important security countermeasures when designing, testing, and releasing your API.\n\nAuthentication\n\n Don't use Basic Auth. Use standard authentication instead (e.g., JWT).\n Don't reinvent the wheel in Authentication, token generation, password storage. Use the standards.\n Use Max Retry and jail features in Login.\n Use encryption on all sensitive data.\n\nJWT (JSON Web Token)\n\n Use a random complicated key (JWT Secret) to make brute forcing the token very hard.\n Don't extract the algorithm from the header. Force the algorithm in the backend (HS256 or RS256).\n Make token expiration (TTL, RTTL) as short as possible.\n Don't store sensitive data in the JWT payload, it can be decoded easily.\n Avoid storing too much data. JWT is usually shared in headers and they have a size limit.\n\nAccess\n\n Limit requests (Throttling) to avoid DDoS / brute-force attacks.\n Use HTTPS on server side with TLS 1.2+ and secure ciphers to avoid MITM (Man in the Middle Attack).\n Use HSTS header with SSL to avoid SSL Strip attacks.\n Turn off directory listings.\n For private APIs, allow access only from safelisted IPs/hosts.\n\nAuthorization\nOAuth\n\n Always validate redirect_uri server-side to allow only safelisted URLs.\n Always try to exchange for code and not tokens (don't allow response_type=token).\n Use state parameter with a random hash to prevent CSRF on the OAuth authorization process.\n Define the default scope, and validate scope parameters for each application.\n\nInput\n\n Use the proper HTTP method according to the operation: GET (read), POST (create), PUT/PATCH (replace/update), and DELETE (to delete a record), and respond with 405 Method Not Allowed if the requested method isn't appropriate for the requested resource.\n Validate content-type on request Accept header (Content Negotiation) to allow only your supported format (e.g., application/xml, application/json, etc.) and respond with 406 Not Acceptable response if not matched.\n Validate content-type of posted data as you accept (e.g., application/x-www-form-urlencoded, multipart/form-data, application/json, etc.).\n Validate user input to avoid common vulnerabilities (e.g., XSS, SQL-Injection, Remote Code Execution, etc.).\n Don't use any sensitive data (credentials, Passwords, security tokens, or API keys) in the URL, but use standard Authorization header.\n Use only server-side encryption.\n Use an API Gateway service to enable caching, Rate Limit policies (e.g., Quota, Spike Arrest, or Concurrent Rate Limit) and deploy APIs resources dynamically.\n\nProcessing\n\n Check if all the endpoints are protected behind authentication to avoid broken authentication process.\n User own resource ID should be avoided. Use /me/orders instead of /user/654321/orders.\n Don't auto-increment IDs. Use UUID instead.\n If you are parsing XML data, make sure entity parsing is not enabled to avoid XXE (XML external entity attack).\n If you are parsing XML, YAML or any other language with anchors and refs, make sure entity expansion is not enabled to avoid Billion Laughs/XML bomb via exponential entity expansion attack.\n Use a CDN for file uploads.\n If you are dealing with huge amount of data, use Workers and Queues to process as much as possible in background and return response fast to avoid HTTP Blocking.\n Do not forget to turn the DEBUG mode OFF.\n Use non-executable stacks when available.\n\nOutput\n\n Send X-Content-Type-Options: nosniff header.\n Send X-Frame-Options: deny header.\n Send Content-Security-Policy: default-src 'none' header.\n Remove fingerprinting headers - X-Powered-By, Server, X-AspNet-Version, etc.\n Force content-type for your response. If you return application/json, then your content-type response is application/json.\n Don't return sensitive data like credentials, passwords, or security tokens.\n Return the proper status code according to the operation completed. (e.g., 200 OK, 400 Bad Request, 401 Unauthorized, 405 Method Not Allowed, etc.).\n\nCI & CD\n\n Audit your design and implementation with unit/integration tests coverage.\n Use a code review process and disregard self-approval.\n Ensure that all components of your services are statically scanned by AV software before pushing to production, including vendor libraries and other dependencies.\n Continuously run security tests (static/dynamic analysis) on your code.\n Check your dependencies (both software and OS) for known vulnerabilities.\n Design a rollback solution for deployments.\n\nMonitoring\n\n Use centralized logins for all services and components.\n Use agents to monitor all traffic, errors, requests, and responses.\n Use alerts for SMS, Slack, Email, Telegram, Kibana, Cloudwatch, etc.\n Ensure that you aren't logging any sensitive data like credit cards, passwords, PINs, etc.\n Use an IDS and/or IPS system to monitor your API requests and instances.\n\n\nSee also:\n\nyosriady/api-development-tools - A collection of useful resources for building RESTful HTTP+JSON APIs.\n\n\nContribution\nFeel free to contribute by forking this repository, making some changes, and submitting pull requests. For any questions drop us an email at team@shieldfy.io."
                ],
                "output": "readability/",
                "pwd": "/data/archive/1736015745.600181",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:37:21.651236+00:00",
                "status": "succeeded"
            }
        ],
        "screenshot": [],
        "singlefile": [],
        "title": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://github.com/shieldfy/API-Security-Checklist"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2025-01-04T18:37:21.565532+00:00",
                "index_texts": null,
                "output": "GitHub - shieldfy/API-Security-Checklist: Checklist of the most important security countermeasures when designing, testing, and releasing your API",
                "pwd": "/data/archive/1736015745.600181",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:37:21.336477+00:00",
                "status": "succeeded"
            }
        ],
        "wget": []
    },
    "icons": null,
    "is_archived": true,
    "is_static": false,
    "latest": {
        "archive_org": "ArchiveError: Failed to find \"content-location\" URL header in Archive.org response.",
        "dom": "output.html",
        "favicon": "favicon.ico",
        "git": null,
        "media": "media/",
        "pdf": null,
        "screenshot": null,
        "singlefile": null,
        "title": "GitHub - shieldfy/API-Security-Checklist: Checklist of the most important security countermeasures when designing, testing, and releasing your API",
        "warc": null,
        "wget": null
    },
    "link_dir": "/data/archive/1736015745.600181",
    "newest_archive_date": "2025-01-04T18:37:53.062286+00:00",
    "num_failures": 1,
    "num_outputs": 8,
    "oldest_archive_date": "2025-01-04T18:37:03.656506+00:00",
    "path": "/shieldfy/API-Security-Checklist",
    "schema": "Link",
    "scheme": "https",
    "snapshot_abid": "snp_01JGS9M4YP1039DB3201HSDWC5",
    "snapshot_id": "2b134538-2743-475a-8f42-c1932396f185",
    "sources": [
        "/data/sources/1736015744-import.txt"
    ],
    "tags": null,
    "tags_str": "",
    "timestamp": "1736015745.600181",
    "title": "GitHub - shieldfy/API-Security-Checklist: Checklist of the most important security countermeasures when designing, testing, and releasing your API",
    "url": "https://github.com/shieldfy/API-Security-Checklist"
}