Learning API Security Made Easy - APISEC University
3 min read

3 min read
Modern web and mobile applications have Application Program Interfaces (APIs). However, many APIs are vulnerable to attacks that businesses are unaware of. This is a rapidly growing topic in the cybersecurity world, as many new companies are developing Software-as-a-Service (SaaS) applications. In this blog, we will introduce a platform that offers numerous resources for learning API Security.
At MRE Security, we are thrilled to announce that we are officially partnered with APISEC/APISEC University. This platform is incredible for learning API Security, and here’s why. Not only do they offer fantastic courses that are entirely free, but each year, they host an APISEC|CON where a group of security professionals discuss various vulnerabilities they have identified in real-world applications and how to begin learning API security.
This means that MRE Security and APISEC will begin producing content to help people learn the fundamentals and advanced skills of API Security. While I cannot go into specifics in this blog, let’s say we have several projects in the works that will be shared soon. Expect to see new videos, walkthroughs, blogs, and more! Let’s not forget about giveaways for certifications.
This partnership is a significant step toward making API security education more accessible and impactful.
As previously stated, all courses are entirely free of charge as of the time of this post. Some of the courses available include how to read API documentation, the OWASP API Top 10, securing API servers, API security fundamentals, and more.
While they offer fantastic courses, they also provide various certifications that can enhance your API security skillset. These certifications are paid but reasonably priced. Here’s a breakdown of the certifications. These certifications do not expire as of the time of this blog post.
Not only is APISec a university, but they also created an automated API scanner. This scanner helps quickly identify vulnerabilities within an API. This is a freemium product, meaning it offers both a free version and a paid pro version. All the user needs is a link to the API documentation or a Postman Collection/OpenAPI-formatted file. You can explore additional options here.
As stated by APISEC, “As APIs have become the foundation of web and mobile applications, securing them is no longer optional—it’s essential.” Don’t miss out on this opportunity. As many new companies start to build various SaaS applications, they will need their APIs tested for vulnerabilities, which will increase the demand for skilled professionals in this field. APISec University does a fantastic job of helping people break into the API security space, providing free courses, certifications, and an automated scanner for both company and personal use. To use the scanner, ensure you have proper permissions to scan the API before proceeding.
Start your API security journey today at apisecuniversity.com.
Lead Technical Writer
Evan is a dedicated cybersecurity professional with a degree from Roger Williams University. He is certified in GRTP, OSCP, eWPTX, eCPPT, and eJPT. He specializes in web application and API security. In his free time, he identifies vulnerabilities in FOSS applications and mentors aspiring cybersecurity professionals.
Learn how to find, report, and publish CVEs using open-source apps. Build skills, earn credibility, and start your penetration testing journey the right way.
May 7, 2025
Penetration testing isn’t just hacking—it's about communication, clear reporting, and delivering real value to clients through actionable findings.
Apr 30, 2025
A complete beginner’s guide to passing the eJPT certification—how to study, what to practice, and why it’s the perfect starting point for ethical hacking.
Apr 16, 2025