API Exposure

Misconfigured Caching

Exposed tokens

JWT Weaknesses

Authorization Issues / IDOR

Undocumented Endpoints

Different Versions

Conventional:

/api/v1/
/api/v2/
/api/beta/

Non-conventional (/api/):

qa
devenv
devenv1
devenv2
preprod
pre-prod
test
testing
staging
stage
dev
development
deploy
slave
master
review
prod
uat
prep
Version2