DEV Community

API

Application Programming Interface

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
My Pay-Per-Call API Was Unpayable — 60 Lines of Python Fixed the x402 Flow

My Pay-Per-Call API Was Unpayable — 60 Lines of Python Fixed the x402 Flow

Comments
3 min read
What Is IDOR? How Can Changing an ID Expose Someone Else's Data?

What Is IDOR? How Can Changing an ID Expose Someone Else's Data?

1
Comments
5 min read
I Built a Pay-Per-Call Tools API That Only Accepts USDC — $0.01 to $0.03 a Call

I Built a Pay-Per-Call Tools API That Only Accepts USDC — $0.01 to $0.03 a Call

Comments
3 min read
A free image-generation API with no key and no account — and the three failures that look like success

A free image-generation API with no key and no account — and the three failures that look like success

Comments
7 min read
Your Recipe App Is Hiding a Silent Video

Your Recipe App Is Hiding a Silent Video

1
Comments
5 min read
GPT-6 Astra, Claude Fable, Gemini 3.8: A Busy Week for New LLM Releases (No Price Changes Though)

GPT-6 Astra, Claude Fable, Gemini 3.8: A Busy Week for New LLM Releases (No Price Changes Though)

Comments
3 min read
Generating request payloads for `oneOf` with `discriminator` in OpenAPI, without generating garbage

Generating request payloads for `oneOf` with `discriminator` in OpenAPI, without generating garbage

Comments
2 min read
HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

Comments
6 min read
Working: HTTP parameter pollution attacks APIs because WAFs evaluate one parameter value while frameworks execute a different one

Working: HTTP parameter pollution attacks APIs because WAFs evaluate one parameter value while frameworks execute a different one

Comments
5 min read
API Versioning: When /api/v1/ Survives Without the Authentication Added in /api/v2/

API Versioning: When /api/v1/ Survives Without the Authentication Added in /api/v2/

Comments
5 min read
Race Conditions in APIs: TOCTOU in Payments, Coupons, and Rate Limiting

Race Conditions in APIs: TOCTOU in Payments, Coupons, and Rate Limiting

Comments
6 min read
CRLF Injection in API Responses: When User Input Reaches HTTP Headers

CRLF Injection in API Responses: When User Input Reaches HTTP Headers

Comments
5 min read
gRPC Security: The Authorization Model REST Scanners Cannot See

gRPC Security: The Authorization Model REST Scanners Cannot See

Comments
5 min read
Mass Assignment in REST APIs: When the Framework Binds More Than It Should

Mass Assignment in REST APIs: When the Framework Binds More Than It Should

Comments
5 min read
Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Comments
6 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.