Detect the API security issue
Find the bug in an API request/response: status codes, headers, JWT, CORS, and more.
About API Detective
Each round shows a tiny request/response scenario. Pick the most accurate root cause. Builds reflexes for status codes, headers, auth, CORS preflight, and content negotiation. Use the related HTTP Headers, cURL Converter, and JWT & OAuth Toolkit for live work.
Runs locally in your browser. Progress is stored only in this browser.
What this challenge teaches
Detect the API security issue is a short drill for API debugging and security review. You are given a request and response pair and need to identify whether the issue is a status code, CORS header, auth token, body shape, or cache/security header.
Example reasoning path
- Read the prompt and identify the artifact type before looking at the answer choices.
- Compare the expected target with each candidate result and eliminate options that are only formatting changes.
- Do not stop at the status code; headers and tokens often explain the real failure.
After you solve it
Open API Debugging Studio to apply the same skill to your own data. For a broader practice loop, return to Skill Challenges or open Workflow Gallery when the task needs multiple tools.
Challenge state stays local to this browser. Do not paste production secrets into practice prompts.
Practice notes for real projects
Use this page as a warm-up before touching real project data. Read the prompt, write down the signal you are looking for, and only then compare answer choices. That habit carries over to production debugging, where the first visible error is often a symptom rather than the root cause.
After the challenge, recreate the same pattern in the linked tool with a harmless sample. For example, replace real tokens, user identifiers, hostnames, and request bodies with safe values, then verify that the same reasoning still works. This keeps practice useful without exposing private data.
- Save time by checking the smallest artifact that reproduces the issue.
- Write one sentence explaining why the wrong answers fail; that explanation is the skill to reuse later.
- If the challenge involves security, treat decoded or inspected data as untrusted until a separate verification step confirms it.
Quick review prompt
Before replaying the challenge, explain the rule in plain language: what input pattern matters, what output shape is expected, and which mistake would cause the wrong answer. That short explanation makes the drill useful outside the game, because it turns a one-click answer into a reusable debugging checklist for code review, QA notes, and incident follow-up.