OWASP website screenshot

OWASP

The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software through community-led open source projects, hundreds of chapters worldwide, and educational resources. OWASP does not provide a centralized public API, but maintains many open source projects, standards (such as the OWASP Top 10 and ASVS), and tools (such as ZAP) that include APIs.

OWASP publishes 1 API on the APIs.io network. Tagged areas include Application Security, Open Source, Security, Web Security, and Standards.

OWASP’s developer surface includes engineering blog, documentation, support, and 7 more developer resources.

21.7/100 emerging ▬ flat Agent 3/100 human only Full breakdown ↓
scored 2026-08-05 · rubric v0.9.1
AccessFreemium
1 APIs
Application SecurityOpen SourceSecurityWeb SecurityStandards

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-05 · rubric v0.9.1
Composite quality — 21.7/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 3.0 / 20
Commercial Clarity 7.9 / 20
Operational Transparency 4.8 / 13
Governance 0.0 / 12
Discoverability 5.9 / 10
Agent readiness — 3/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/owasp: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

OWASP

Open Worldwide Application Security Project providing resources, tools, projects, and standards for application and web security.

Pricing Plans 1

Published pricing tiers and plan structures.

Owasp Plans Pricing

3 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Owasp Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Owasp Finops

FINOPS

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Owasp Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Owasp Vulnerability Disclosure

security.txt · contact published

SECURITY

Resources

Documentation 1

Reference material describing how the API behaves

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: owasp
name: OWASP
description: The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security
  of software through community-led open source projects, hundreds of chapters worldwide, and educational resources. OWASP
  does not provide a centralized public API, but maintains many open source projects, standards (such as the OWASP Top 10
  and ASVS), and tools (such as ZAP) that include APIs.
type: Index
accessModel:
  pricing: freemium
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Freemium
  confidence: medium
  source:
  - plans
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/owasp.png
tags:
- Application Security
- Open Source
- Security
- Web Security
- Standards
url: https://raw.githubusercontent.com/api-evangelist/owasp/refs/heads/main/apis.yml
created: '2026-03-16'
modified: '2026-04-28'
specificationVersion: '0.19'
apis:
- aid: owasp:owasp
  name: OWASP
  description: Open Worldwide Application Security Project providing resources, tools, projects, and standards for application
    and web security.
  humanURL: https://owasp.org/
  tags:
  - Application Security
  - Security
  - Web Security
  - Standards
  properties:
  - type: Documentation
    url: https://owasp.org/
  - type: GettingStarted
    url: https://owasp.org/getting-started/
  - type: Projects
    url: https://owasp.org/projects/
  - type: GitHubOrganization
    url: https://github.com/OWASP
common:
- type: VulnerabilityDisclosure
  url: security/owasp-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/owasp-domain-security.yml
- url: https://owasp.org/feed.xml
  type: Blog
- type: LinkedIn
  url: https://www.linkedin.com/company/owasp
- type: Website
  url: https://owasp.org/
- type: Documentation
  url: https://owasp.org/projects/
- type: Community
  url: https://owasp.org/slack/invite
- type: GitHubOrganization
  url: https://github.com/OWASP
- type: Support
  url: https://owasp.org/contact/
- type: Foundation
  url: https://owasp.org/www-policy/
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com