The practice of protecting application programming interfaces from attacks that could expose data or disrupt services.
As more applications rely on APIs to communicate with each other, they've become a common attack surface. API security covers authentication, rate limiting, input validation, and monitoring for abuse — skills covered directly in our penetration testing curriculum.