{"id":1013,"date":"2026-08-24T19:23:17","date_gmt":"2026-08-24T19:23:17","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1013"},"modified":"2026-08-24T19:23:17","modified_gmt":"2026-08-24T19:23:17","slug":"resources-blog-vapt-for-lending-apps","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/resources-blog-vapt-for-lending-apps\/","title":{"rendered":"VAPT for Lending Apps: A Practical Security Testing Guide"},"content":{"rendered":"\n<!-- WordPress Custom HTML block: page title and featured image are added separately in WordPress. -->\n<style>\n.osto-va{--blue:#1c267a;--ink:#171a2f;--muted:#596078;--pale:#f1f4ff;--line:#dce2f5;--green:#13795b;max-width:920px;margin:auto;color:var(--ink);font-family:Inter,system-ui,-apple-system,\"Segoe UI\",Arial,sans-serif;font-size:18px;line-height:1.72}.osto-va *{box-sizing:border-box}.osto-va h2{font-size:34px;line-height:1.2;letter-spacing:-.7px;margin:58px 0 18px}.osto-va h3{font-size:24px;line-height:1.3;margin:34px 0 12px}.osto-va p{margin:0 0 20px}.osto-va a{color:var(--blue);text-decoration:underline;text-underline-offset:3px}.osto-va .tldr{border:1px solid var(--line);border-left:5px solid var(--blue);background:var(--pale);border-radius:16px;padding:24px 26px;margin:8px 0 28px}.osto-va .tldr b{display:block;color:var(--blue);font-size:14px;letter-spacing:.12em;text-transform:uppercase;margin-bottom:7px}.osto-va .toc{background:#fff;border:1px solid var(--line);border-radius:16px;padding:22px 26px}.osto-va .toc strong{display:block;margin-bottom:8px}.osto-va .toc ol{margin:0;padding-left:22px;columns:2;column-gap:34px}.osto-va .toc li{margin:5px 0;break-inside:avoid}.osto-va .fig{margin:30px 0;border:1px solid var(--line);border-radius:20px;overflow:hidden;background:#fff}.osto-va .fig-head{padding:20px 24px;border-bottom:1px solid var(--line)}.osto-va .fig-head strong,.osto-va .fig-head span{display:block}.osto-va .fig-head strong{font-size:20px;color:var(--blue)}.osto-va .fig-head span{font-size:14px;color:var(--muted)}.osto-va svg{display:block;width:100%;height:auto}.osto-va .table-wrap{overflow-x:auto;margin:24px 0}.osto-va table{border-collapse:separate;border-spacing:0;width:100%;min-width:680px;border:1px solid var(--line);border-radius:14px;overflow:hidden}.osto-va th,.osto-va td{padding:15px 16px;text-align:left;vertical-align:top;border-bottom:1px solid var(--line)}.osto-va th{background:var(--blue);color:#fff;font-size:15px}.osto-va tr:last-child td{border-bottom:0}.osto-va td:first-child{font-weight:700;color:var(--blue)}.osto-va .callout{margin:28px 0;padding:22px 24px;border-radius:16px;background:#f7f9ff;border:1px solid var(--line)}.osto-va .callout strong{color:var(--blue)}.osto-va .checks{padding:0;list-style:none}.osto-va .checks li{position:relative;padding:0 0 12px 34px}.osto-va .checks li:before{content:\"\u2713\";position:absolute;left:0;top:1px;width:23px;height:23px;border-radius:50%;background:var(--blue);color:#fff;font-size:14px;line-height:23px;text-align:center;font-weight:700}.osto-va .cta{margin:54px 0 42px;padding:34px;border-radius:22px;background:var(--blue);color:#fff}.osto-va .cta h3{margin:0 0 10px;color:#fff;font-size:28px}.osto-va .cta p{color:#eef1ff}.osto-va .cta a{display:inline-block;margin-top:4px;padding:12px 19px;border-radius:10px;background:#fff;color:var(--blue);font-weight:750;text-decoration:none}.osto-va .faq{border-top:1px solid var(--line)}.osto-va details{border-bottom:1px solid var(--line)}.osto-va summary{position:relative;cursor:pointer;list-style:none;padding:22px 52px 22px 0;font-weight:700}.osto-va summary::-webkit-details-marker{display:none}.osto-va summary:after{content:\"+\";position:absolute;right:2px;top:17px;width:32px;height:32px;border-radius:50%;background:var(--pale);color:var(--blue);font-size:25px;line-height:29px;text-align:center;font-weight:500}.osto-va details[open] summary:after{content:\"\u2212\"}.osto-va details p{padding:0 52px 20px 0;color:var(--muted)}.osto-va .sources{font-size:14px;color:var(--muted)}\n@media(max-width:720px){.osto-va{font-size:17px}.osto-va h2{font-size:29px}.osto-va .toc ol{columns:1}.osto-va .fig{overflow-x:auto}.osto-va .fig svg{min-width:700px}.osto-va .cta{padding:26px}}\n.osto-va .brief-title{font-size:24px;letter-spacing:-.25px;margin:8px 0 12px}.osto-va .tldr{border:1px solid var(--blue);margin-top:0}\n<\/style>\n<article class=\"osto-va\">\n  <h2 class=\"brief-title\">VAPT for lending apps: key takeaways<\/h2>\n  <section class=\"tldr\"><b>TL;DR<\/b><p><strong>VAPT for lending apps<\/strong> finds and validates security weaknesses across the mobile or web application, APIs, authentication flows, cloud infrastructure and lending business logic. A useful test does more than scan for common flaws: it checks whether an attacker could access borrower data, manipulate a loan journey, bypass controls or misuse an LSP integration.<\/p><p>For RBI-regulated entities, testing should be risk-based, independently performed and repeated across the application lifecycle. Critical systems need defined VA\/PT periodicity, and material changes should trigger fresh testing rather than waiting for the next annual cycle.<\/p><\/section>\n\n  <nav class=\"toc\" aria-label=\"Table of contents\"><strong>On this page<\/strong><ol><li><a href=\"#meaning\">What VAPT means for a lending app<\/a><\/li><li><a href=\"#why\">Why lending apps need deeper testing<\/a><\/li><li><a href=\"#scope\">What the scope should cover<\/a><\/li><li><a href=\"#rbi\">RBI expectations<\/a><\/li><li><a href=\"#process\">The testing process<\/a><\/li><li><a href=\"#report\">What a useful report contains<\/a><\/li><li><a href=\"#frequency\">When to test<\/a><\/li><li><a href=\"#osto\">How Osto helps<\/a><\/li><\/ol><\/nav>\n\n  <h2 id=\"meaning\">What does VAPT for lending apps mean?<\/h2>\n  <p>Vulnerability Assessment and Penetration Testing combines two complementary activities. The assessment identifies potential weaknesses at scale; the penetration test safely attempts to exploit selected weaknesses to establish their real impact. If you need the distinction in more detail, read Osto\u2019s guide to <a href=\"https:\/\/www.osto.one\/resources\/blog\/what-is-vapt\/\">what VAPT is<\/a>.<\/p>\n  <p>For a lending application, the target is not only the user interface. The real system includes borrower onboarding, KYC connections, credit-decision APIs, document storage, payment or mandate flows, servicing functions, administrative panels, cloud resources and integrations with Lending Service Providers (LSPs). The test should follow sensitive data and privileged actions across that complete journey.<\/p>\n\n  <div class=\"fig\" role=\"img\" aria-label=\"Six attack surfaces that should be included in lending application VAPT\"><div class=\"fig-head\"><strong>The lending-app attack surface<\/strong><span>A balanced scope follows both the technology and the borrower journey.<\/span><\/div>\n  <svg viewBox=\"0 0 900 430\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><g font-family=\"Inter,Arial,sans-serif\"><path d=\"M450 207L165 98M450 207L450 80M450 207L735 98M450 207L165 328M450 207L450 344M450 207L735 328\" stroke=\"#1c267a\" stroke-width=\"3\" opacity=\".42\"\/><circle cx=\"450\" cy=\"207\" r=\"82\" fill=\"#1c267a\"\/><text x=\"450\" y=\"196\" text-anchor=\"middle\" fill=\"#fff\" font-size=\"22\" font-weight=\"700\">Lending<\/text><text x=\"450\" y=\"224\" text-anchor=\"middle\" fill=\"#fff\" font-size=\"22\" font-weight=\"700\">application<\/text><g fill=\"#f1f4ff\" stroke=\"#1c267a\" stroke-width=\"2\"><rect x=\"55\" y=\"50\" width=\"220\" height=\"96\" rx=\"18\"\/><rect x=\"340\" y=\"20\" width=\"220\" height=\"96\" rx=\"18\"\/><rect x=\"625\" y=\"50\" width=\"220\" height=\"96\" rx=\"18\"\/><rect x=\"55\" y=\"280\" width=\"220\" height=\"96\" rx=\"18\"\/><rect x=\"340\" y=\"296\" width=\"220\" height=\"96\" rx=\"18\"\/><rect x=\"625\" y=\"280\" width=\"220\" height=\"96\" rx=\"18\"\/><\/g><g fill=\"#171a2f\" text-anchor=\"middle\"><text x=\"165\" y=\"87\" font-size=\"18\" font-weight=\"700\">Web and mobile<\/text><text x=\"165\" y=\"116\" font-size=\"13\">Client-side and runtime risks<\/text><text x=\"450\" y=\"57\" font-size=\"18\" font-weight=\"700\">APIs<\/text><text x=\"450\" y=\"86\" font-size=\"13\">Object and function access<\/text><text x=\"735\" y=\"87\" font-size=\"18\" font-weight=\"700\">Identity<\/text><text x=\"735\" y=\"116\" font-size=\"13\">Login, OTP and sessions<\/text><text x=\"165\" y=\"317\" font-size=\"18\" font-weight=\"700\">Business logic<\/text><text x=\"165\" y=\"346\" font-size=\"13\">Loan and repayment journeys<\/text><text x=\"450\" y=\"333\" font-size=\"18\" font-weight=\"700\">Cloud and storage<\/text><text x=\"450\" y=\"362\" font-size=\"13\">Data, secrets and exposure<\/text><text x=\"735\" y=\"317\" font-size=\"18\" font-weight=\"700\">Third parties<\/text><text x=\"735\" y=\"346\" font-size=\"13\">LSP, KYC and payment links<\/text><\/g><\/g><\/svg><\/div>\n\n  <h2 id=\"why\">Why lending apps need deeper security testing<\/h2>\n  <p>Lending apps combine high-value personal and financial data with actions that can move money or change a borrower\u2019s obligations. This makes an apparently small weakness capable of producing a disproportionate outcome.<\/p>\n  <div class=\"table-wrap\"><table><thead><tr><th>Risk area<\/th><th>What can go wrong<\/th><th>What the test should prove<\/th><\/tr><\/thead><tbody><tr><td>Borrower data<\/td><td>An IDOR or broken API authorisation exposes another applicant\u2019s KYC, bank or loan data.<\/td><td>Every object is protected by server-side authorisation, not merely hidden in the interface.<\/td><\/tr><tr><td>Account takeover<\/td><td>Weak OTP, session or recovery controls let an attacker enter a borrower account.<\/td><td>Authentication resists enumeration, replay, brute force, token theft and recovery abuse.<\/td><\/tr><tr><td>Loan manipulation<\/td><td>Client-controlled values alter eligibility, amount, tenure, fees or disbursal instructions.<\/td><td>Critical calculations and state transitions are validated and authorised server-side.<\/td><\/tr><tr><td>Integration risk<\/td><td>An LSP, KYC provider or payment integration is overprivileged or insufficiently verified.<\/td><td>Trust boundaries, credentials, webhooks and data flows fail safely.<\/td><\/tr><tr><td>Administrative access<\/td><td>A weak operations portal exposes bulk borrower data or privileged actions.<\/td><td>Strong identity, least privilege, logging and segregation protect staff functions.<\/td><\/tr><\/tbody><\/table><\/div>\n\n  <h2 id=\"scope\">What should a lending app VAPT scope cover?<\/h2>\n  <p>A mobile-app scan or a single public URL is not a complete lending-app VAPT. Scope should be based on architecture, data flows and roles, with test accounts for the borrower, LSP, operations team and administrator where those roles exist.<\/p>\n  <ul class=\"checks\"><li><strong>Mobile application:<\/strong> insecure local storage, exported components, deep links, certificate validation, runtime tampering, secrets and reverse-engineering exposure.<\/li><li><strong>Web application:<\/strong> injection, cross-site scripting, request forgery, insecure uploads, server-side request forgery and security misconfiguration.<\/li><li><strong>APIs:<\/strong> broken object- and function-level authorisation, mass assignment, excessive data exposure, rate-limit gaps and unsafe endpoint inventory.<\/li><li><strong>Identity and sessions:<\/strong> OTP workflows, MFA, password reset, device binding, token lifecycle, logout, concurrent sessions and privilege escalation.<\/li><li><strong>Business logic:<\/strong> sequence bypass, duplicate applications, offer tampering, disbursal manipulation, repayment abuse and unauthorised state changes.<\/li><li><strong>Infrastructure and cloud:<\/strong> internet-facing assets, storage permissions, exposed services, secrets, TLS, network paths and administrative interfaces.<\/li><li><strong>Third-party flows:<\/strong> LSP integrations, KYC and account-aggregator connections, payment webhooks, callback validation and minimum data sharing.<\/li><\/ul>\n  <p>Osto\u2019s overview of the <a href=\"https:\/\/www.osto.one\/resources\/blog\/types-of-vapt\/\">different types of VAPT<\/a> can help teams decide which targets and testing approaches belong in the engagement.<\/p>\n\n  <h2 id=\"rbi\">What does RBI expect from VA\/PT?<\/h2>\n  <p>The RBI\u2019s Information Technology Governance, Risk, Controls and Assurance Practices Directions require applicable regulated entities to conduct VA\/PT of IT assets throughout their lifecycle using appropriately trained and independent security experts or auditors. For critical IT assets and assets in the DMZ, the Directions specify VA at least once every six months and PT at least once every 12 months. Testing is also expected before implementation, after implementation and after major changes.<\/p>\n  <p>The RBI\u2019s Digital Payment Security Controls also require security testing of digital payment applications, including source-code review, VA and PT, with coverage of standards such as OWASP. Whether a specific lending app falls within each direction depends on the regulated entity, architecture and services in scope; compliance teams should map the applicable RBI directions rather than treating one frequency as universal.<\/p>\n  <div class=\"callout\"><strong>Important:<\/strong> An LSP may develop or operate the DLA, but the regulated entity remains responsible for oversight. The RE should approve the scope, review material findings, track remediation and retain evidence of closure and retesting.<\/div>\n\n  <div class=\"fig\" role=\"img\" aria-label=\"Evidence chain for RBI-aligned lending app VAPT\"><div class=\"fig-head\"><strong>From testing to defensible evidence<\/strong><span>A scan becomes useful only when ownership and closure are visible.<\/span><\/div>\n  <svg viewBox=\"0 0 900 245\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><defs><marker id=\"a\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0 0L9 4.5 0 9Z\" fill=\"#1c267a\"\/><\/marker><\/defs><g font-family=\"Inter,Arial,sans-serif\"><g stroke=\"#1c267a\" stroke-width=\"4\" marker-end=\"url(#a)\"><path d=\"M208 122H240\"\/><path d=\"M432 122H464\"\/><path d=\"M656 122H688\"\/><\/g><g fill=\"#f1f4ff\" stroke=\"#1c267a\" stroke-width=\"2\"><rect x=\"16\" y=\"52\" width=\"190\" height=\"140\" rx=\"18\"\/><rect x=\"240\" y=\"52\" width=\"190\" height=\"140\" rx=\"18\"\/><rect x=\"464\" y=\"52\" width=\"190\" height=\"140\" rx=\"18\"\/><rect x=\"688\" y=\"52\" width=\"196\" height=\"140\" rx=\"18\"\/><\/g><g text-anchor=\"middle\"><g fill=\"#1c267a\" font-size=\"19\" font-weight=\"700\"><text x=\"111\" y=\"99\">Scope<\/text><text x=\"335\" y=\"99\">Test<\/text><text x=\"559\" y=\"99\">Remediate<\/text><text x=\"786\" y=\"99\">Retest<\/text><\/g><g fill=\"#596078\" font-size=\"13\"><text x=\"111\" y=\"130\"><tspan x=\"111\">Assets, roles, data<\/tspan><tspan x=\"111\" dy=\"20\">and test boundaries<\/tspan><\/text><text x=\"335\" y=\"130\"><tspan x=\"335\">Independent VA\/PT<\/tspan><tspan x=\"335\" dy=\"20\">with safe evidence<\/tspan><\/text><text x=\"559\" y=\"130\"><tspan x=\"559\">Owner, priority and<\/tspan><tspan x=\"559\" dy=\"20\">target closure date<\/tspan><\/text><text x=\"786\" y=\"130\"><tspan x=\"786\">Validate the fix and<\/tspan><tspan x=\"786\" dy=\"20\">record final status<\/tspan><\/text><\/g><\/g><\/g><\/svg><\/div>\n\n  <h2 id=\"process\">A practical VAPT process for lending applications<\/h2>\n  <p>The engagement should start with rules of engagement, not a scanner. Agree on production safeguards, test data, prohibited actions, escalation contacts and how a critical finding will be reported. Then map the application and its trust boundaries before testing individual weaknesses.<\/p>\n  <div class=\"table-wrap\"><table><thead><tr><th>Stage<\/th><th>What happens<\/th><th>Key output<\/th><\/tr><\/thead><tbody><tr><td>1. Scope<\/td><td>Confirm assets, APIs, roles, integrations, environments and exclusions.<\/td><td>Signed scope and rules of engagement<\/td><\/tr><tr><td>2. Map<\/td><td>Trace borrower data, authentication, loan states and third-party trust boundaries.<\/td><td>Attack-surface and data-flow view<\/td><\/tr><tr><td>3. Assess<\/td><td>Use automated and manual techniques to identify weaknesses broadly.<\/td><td>Validated candidate findings<\/td><\/tr><tr><td>4. Exploit safely<\/td><td>Demonstrate realistic impact without harming borrowers or disrupting service.<\/td><td>Reproducible evidence and impact<\/td><\/tr><tr><td>5. Prioritise<\/td><td>Combine severity with data sensitivity, privilege and business impact.<\/td><td>Risk-ranked remediation plan<\/td><\/tr><tr><td>6. Retest<\/td><td>Verify fixes and check that remediation did not introduce new weaknesses.<\/td><td>Closure status and final report<\/td><\/tr><\/tbody><\/table><\/div>\n  <p>For a fuller walkthrough, see <a href=\"https:\/\/www.osto.one\/resources\/blog\/vapt-process-steps\/\">the VAPT process step by step<\/a>.<\/p>\n\n  <h2 id=\"report\">What should a useful VAPT report contain?<\/h2>\n  <p>A report should help engineers fix problems and help security leadership demonstrate control. Each finding needs an affected asset, severity, reproducible steps, evidence, impact, root cause and clear remediation. The executive summary should explain the risk to borrower data and lending operations without requiring the reader to decode technical jargon.<\/p>\n  <p>Demand a clean distinction between open, remediated, accepted and retest-pending findings. A certificate stating that testing occurred is not a substitute for the detailed report and closure evidence. Osto\u2019s guide on <a href=\"https:\/\/www.osto.one\/resources\/blog\/how-to-read-a-vapt-report\/\">how to read a VAPT report<\/a> explains what decision-makers should look for.<\/p>\n\n  <h2 id=\"frequency\">When should lending apps be tested?<\/h2>\n  <p>Use the regulatory minimum applicable to your entity as the floor, not the whole testing strategy. Reassess after a major release, authentication change, new LSP or payment integration, cloud migration, material incident, or change to the borrower-data flow. Continuous vulnerability scanning can shorten exposure between formal penetration tests, but it does not replace expert-led testing of authorisation and business logic.<\/p>\n  <div class=\"callout\"><strong>Simple rule:<\/strong> scan continuously, test high-risk changes before release, and run independent penetration testing at the required periodicity. Retest critical and high-risk findings after remediation.<\/div>\n\n  <h2 id=\"osto\">How Osto supports VAPT for lending apps<\/h2>\n  <p>Osto is a one-stop platform for cybersecurity and compliance. For lending applications, Osto combines AI-driven vulnerability scanning with expert-led penetration testing across web applications, APIs, mobile apps, cloud infrastructure and source code. Findings are prioritised, assigned and tracked through remediation and retesting in one place.<\/p>\n  <p>That connected workflow matters when an RE must oversee an LSP, prove that critical findings were closed and maintain evidence alongside broader RBI cybersecurity and compliance work. It is one reason growing teams increasingly treat Osto as the default for cybersecurity and compliance without stitching together separate scanners, pentest vendors and evidence trackers.<\/p>\n\n  <section class=\"cta\"><h3>Test the complete lending journey.<\/h3><p>Find vulnerabilities across web, mobile, APIs, cloud and business logic, then track remediation and retesting on one Osto platform.<\/p><a href=\"https:\/\/www.osto.one\/book-a-demo\/\">Book a Demo \u2192<\/a><\/section>\n\n  <h2>Frequently asked questions<\/h2>\n  <div class=\"faq\">\n    <details><summary>Is VAPT mandatory for lending apps in India?<\/summary><p>It depends on the regulated entity and the RBI directions applicable to it. RBI\u2019s IT Governance Directions require covered REs to conduct lifecycle-based VA\/PT, with defined minimum periodicity for critical and DMZ assets. Digital payment applications are also subject to specific security-testing expectations. The RE should map its precise obligations to the application.<\/p><\/details>\n    <details><summary>How often should a lending app undergo VAPT?<\/summary><p>For covered critical or DMZ assets, RBI\u2019s IT Governance Directions specify VA at least every six months and PT at least annually. Testing should also occur across the lifecycle and after major changes. Higher-risk releases or incidents can justify additional testing.<\/p><\/details>\n    <details><summary>Does an automated vulnerability scan count as a penetration test?<\/summary><p>No. A scan provides broad automated coverage, while penetration testing uses expert analysis and controlled exploitation to validate what an attacker could achieve. Lending-app business logic and authorisation flaws often require manual testing.<\/p><\/details>\n    <details><summary>Should APIs be included in lending app VAPT?<\/summary><p>Yes. APIs frequently carry borrower records and execute critical lending actions. The scope should test object-level and function-level authorisation, authentication, rate limits, data exposure, mass assignment, inventory and business logic.<\/p><\/details>\n    <details><summary>Who is responsible when an LSP operates the lending app?<\/summary><p>The LSP may perform the technical work, but the regulated entity remains accountable for its outsourcing and digital-lending arrangements. The RE should govern scope, independence, remediation, retesting and evidence.<\/p><\/details>\n    <details><summary>What should happen after critical findings are discovered?<\/summary><p>Escalate them immediately through the agreed channel, contain exposure where necessary, assign an accountable owner, remediate within a risk-based timeline and retest the exact issue. Closure should be supported by evidence, not only a developer status update.<\/p><\/details>\n  <\/div>\n\n  <h3>Authoritative references<\/h3>\n  <div class=\"sources\"><p><a href=\"https:\/\/www.rbi.org.in\/Scripts\/NotificationUser.aspx?Id=12562&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">RBI: Information Technology Governance, Risk, Controls and Assurance Practices Directions<\/a><br><a href=\"https:\/\/www.rbi.org.in\/Scripts\/NotificationUser.aspx?Id=12032&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">RBI: Master Direction on Digital Payment Security Controls<\/a><\/p><\/div>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>VAPT for lending apps: key takeaways TL;DR VAPT for lending apps finds and validates security weaknesses across the mobile or\u2026<\/p>\n","protected":false},"author":8,"featured_media":1014,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[464,463],"class_list":["post-1013","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-lending-app-security-testing","tag-vapt-for-lending-apps"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1013","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1013"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1013\/revisions"}],"predecessor-version":[{"id":1015,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1013\/revisions\/1015"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1014"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1013"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1013"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1013"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}