Cloudflare AppSec Lab API · Playground · santos.rwxorange.com
Interactive API Playground

AppSec Lab API — click, run, watch the edge decide.

Every request goes through Cloudflare’s edge before reaching this origin. Interactive reference: Swagger /docs · openapi.json (for API Shield schema validation)

Service

GET/api/health

Liveness check.

POST/echo

Diagnostics: shows exactly what reached the origin — method, headers, cf-ray, body. If an attack was blocked at the edge, this never fires.

Catalog (public)

GET/api/customers

List all customers (fake data).

GET/api/customers/1

Fetch one customer by id.

Schema validation demo (API Shield)

POST/api/customers

Valid payload — passes schema and reaches the origin (201 Created).

After enabling API Shield schema validation, attacks like the one below are blocked at the edge with 403 — Security Events shows the rule.

POST/api/customers

Malformed payload — invalid tier and string credit limit. Today the origin rejects it (422); with API Shield it is blocked at the edge before this server.

Auth flow (JWT)

POST/api/login

Issues a demo JWT (HS256). The token is kept in your browser and used by the orders calls.

GET/api/orders

Protected route — requires a valid bearer token.