{"id":639,"date":"2026-08-13T05:47:56","date_gmt":"2026-08-13T05:47:56","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=639"},"modified":"2026-08-13T05:47:56","modified_gmt":"2026-08-13T05:47:56","slug":"api-security","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/api-security\/","title":{"rendered":"API Security: Risks and Controls That Work"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: API SECURITY\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">API security is the practice of protecting the endpoints your applications expose, where the main risk is not a malformed payload but a valid request asking for someone else&#8217;s data.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Application security<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>API security covers discovering every endpoint you expose, authenticating and authorising each request, validating what comes in, limiting how often it can be called, and monitoring for abuse. The dominant risk category is broken authorisation: an authenticated user requesting a record that belongs to someone else.<\/p>\n<\/div>\n\n<p>Web application security assumes a browser and a human. APIs have neither. There is no page to render, no session cookie to lean on, and the client is often another machine, which is why attacks look like ordinary traffic.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#inventory\">You cannot protect what you have not found<\/a><\/li>\n    <li><a href=\"#risks\">The risks that matter most<\/a><\/li>\n    <li><a href=\"#controls\">Controls that work<\/a><\/li>\n    <li><a href=\"#osto\">How Osto protects APIs<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"inventory\">You cannot protect what you have not found<\/h2>\n\n<p>Most API incidents involve an endpoint nobody was tracking: a version left running after a migration, an internal service quietly reachable from the internet, a debug route that shipped.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 260\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Documented APIs versus what discovery finds, including undocumented, deprecated and internal endpoints.\">\n  <text x=\"20\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">WHAT AN API INVENTORY USUALLY LOOKS LIKE<\/text>\n\n  <rect x=\"16\" y=\"48\" width=\"200\" height=\"180\" rx=\"16\" fill=\"#e3f0e9\"\/>\n  <text x=\"116\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#3a6f5d\">Documented<\/text>\n  <text x=\"116\" y=\"98\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">In the spec, reviewed,<\/text>\n  <text x=\"116\" y=\"114\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">tested, monitored<\/text>\n  <rect x=\"40\" y=\"132\" width=\"152\" height=\"26\" rx=\"8\" fill=\"#ffffff\"\/><text x=\"116\" y=\"150\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#3a6f5d\">\/v2\/users<\/text>\n  <rect x=\"40\" y=\"164\" width=\"152\" height=\"26\" rx=\"8\" fill=\"#ffffff\"\/><text x=\"116\" y=\"182\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#3a6f5d\">\/v2\/orders<\/text>\n  <rect x=\"40\" y=\"196\" width=\"152\" height=\"26\" rx=\"8\" fill=\"#ffffff\"\/><text x=\"116\" y=\"214\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#3a6f5d\">\/v2\/billing<\/text>\n\n  <text x=\"252\" y=\"146\" font-family=\"Inter,sans-serif\" font-size=\"26\" fill=\"#c3c9f0\">+<\/text>\n\n  <rect x=\"292\" y=\"48\" width=\"452\" height=\"180\" rx=\"16\" fill=\"#fdf6f0\"\/>\n  <text x=\"518\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#a2603a\">What discovery finds<\/text>\n  <text x=\"518\" y=\"98\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Live, reachable, and outside every process you have<\/text>\n\n  <rect x=\"312\" y=\"118\" width=\"196\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"410\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#a2603a\">\/v1\/users &#183; deprecated, still up<\/text>\n  <rect x=\"528\" y=\"118\" width=\"196\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"626\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#a2603a\">\/internal\/admin &#183; not internal<\/text>\n  <rect x=\"312\" y=\"156\" width=\"196\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"410\" y=\"176\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#a2603a\">\/debug\/config &#183; shipped by accident<\/text>\n  <rect x=\"528\" y=\"156\" width=\"196\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"626\" y=\"176\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#a2603a\">\/partner\/export &#183; no rate limit<\/text>\n  <rect x=\"312\" y=\"194\" width=\"412\" height=\"26\" rx=\"8\" fill=\"#f2cdb2\"\/>\n  <text x=\"518\" y=\"212\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#7e4426\">These are the ones attacked, because nobody is watching them<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Deprecated versions and internal endpoints are the two categories that show up most often in API breach reports.<\/figcaption>\n<\/figure>\n\n<h2 id=\"risks\" class=\"c-sage\">The risks that matter most<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Risk<\/th><th>What it looks like<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Broken object level authorisation<\/strong><\/td><td>Changing an ID in the request returns another customer&#8217;s record. The top entry in the OWASP API Security Top 10.<\/td><\/tr>\n    <tr><td><strong>Broken authentication<\/strong><\/td><td>Tokens that never expire, weak signing, or endpoints that forgot to require a token at all.<\/td><\/tr>\n    <tr><td><strong>Excessive data exposure<\/strong><\/td><td>The endpoint returns the full object and expects the client to hide the sensitive fields.<\/td><\/tr>\n    <tr><td><strong>No rate limiting<\/strong><\/td><td>An endpoint that can be called endlessly, enabling enumeration and scraping.<\/td><\/tr>\n    <tr><td><strong>Shadow and zombie endpoints<\/strong><\/td><td>Live routes outside the spec, unmonitored and usually <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-gap-analysis\/\">unpatched<\/a>.<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Why scanners miss the worst of it<\/p>\n  <p>An authorisation flaw is a perfectly formed request from a valid account. There is no malicious payload to match against a signature, which is why broken object level authorisation is found by testers and by behavioural analysis rather than by a scanner.<\/p>\n<\/div>\n\n<h2 id=\"controls\" class=\"c-apri\">Controls that work<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Authorise per object<\/p>\n    <p>Check ownership on every request, at the data layer. Never trust an ID supplied by the client.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Validate against a schema<\/p>\n    <p>Accept only the fields, types and methods the endpoint expects, and reject the rest.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Limit and monitor<\/p>\n    <p>Rate limits per client, plus alerting on volume patterns that look like enumeration.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto protects APIs<\/h2>\n\n<p>Osto discovers applications and APIs automatically and applies protection to what it finds, which closes the inventory gap that most API incidents begin with. The engine learns each endpoint&#8217;s normal behaviour and generates a positive security policy: expected URLs, parameters, methods and types are allowed, and anything outside that profile is rejected. Cookie security, file upload validation and protection against forced browsing and parameter pollution are enforced at the same layer, and policy recommendations continue as the API changes.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Find the endpoints nobody documented<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto discovers your applications and APIs automatically and applies protection to what it finds, including the versions you forgot were live.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Automatic API discovery &middot; Schema enforcement &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is API security?<\/summary>\n  <p>The practice of protecting the endpoints an application exposes: discovering every endpoint, authenticating and authorising each request, validating inputs, rate limiting, and monitoring for abuse.<\/p>\n<\/details>\n\n<details>\n  <summary>What is BOLA?<\/summary>\n  <p>Broken object level authorisation. An authenticated user requests an object belonging to someone else, usually by changing an identifier in the request, and the API returns it because it checked who the user was but not what they were entitled to see.<\/p>\n<\/details>\n\n<details>\n  <summary>Is a WAF enough to secure an API?<\/summary>\n  <p>Not on its own. A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> blocks malicious payloads and enforces expected structure, which handles a large share of automated attacks. Authorisation logic still has to be correct in the application, because a valid request for the wrong record looks legitimate at the edge.<\/p>\n<\/details>\n\n<details>\n  <summary>What are shadow and zombie APIs?<\/summary>\n  <p>Shadow APIs are endpoints running outside the documented inventory. Zombie APIs are older versions left live after a newer one shipped. Both are usually unmonitored and unpatched, which is why discovery is the first control.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> &middot; OWASP Top 10 &middot; DAST &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">Penetration Testing<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a> &middot; Rate Limiting<\/p>\n\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>API security is the practice of protecting the endpoints your applications expose, where the main risk is not a malformed\u2026<\/p>\n","protected":false},"author":8,"featured_media":640,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[227,224,225,226],"class_list":["post-639","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-api-discovery","tag-api-security","tag-shadow-api","tag-zombie-api"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=639"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/639\/revisions"}],"predecessor-version":[{"id":641,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/639\/revisions\/641"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/640"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=639"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=639"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}