Overview & safe testing rules
APIs are high-value attack surfaces. Always get written authorization before testing. Prefer non-production test environments, throttle your probes, and keep logs of every request and response. Never attempt account takeover, destructive actions, or data exfiltration on live systems without explicit permission.

Scope, authorization, and minimizing impact.