All glossary terms
Glossary

API abuse

API abuse is using an application's APIs in ways they weren't meant to be used, such as scraping data, enumerating accounts, or calling expensive endpoints at high volume, often with valid credentials.

Unlike classic attacks, API abuse often uses well-formed, authenticated requests. Signature-based WAF rules see nothing wrong with them.

Catching it requires knowing each API's normal behavior: who calls which endpoints, how often, with what parameters. The impact shows up as data loss, inflated cloud bills or degraded service.

Where Huskeys fits

Huskeys profiles each application's API traffic and flags abuse patterns, including those driving up traffic costs.

Related terms

Further reading