{"id":676,"date":"2026-08-13T11:23:30","date_gmt":"2026-08-13T11:23:30","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=676"},"modified":"2026-08-13T11:23:30","modified_gmt":"2026-08-13T11:23:30","slug":"dast","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/dast\/","title":{"rendered":"DAST Explained: Dynamic Application Security Testing"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: DAST\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">DAST tests a running application from the outside, sending real requests the way an attacker would, to find weaknesses that only appear once the code is deployed.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Application security<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>DAST stands for dynamic application security testing. A DAST scanner crawls your live application, submits crafted inputs to every form, parameter and endpoint it finds, and reports where the application responds in a way that reveals a vulnerability. It sees no source code, which is why DAST finds different problems from SAST.<\/p>\n<\/div>\n\n<p>The distinction that matters: SAST reads what the code says, DAST observes what the deployed application actually does. A flaw introduced by a misconfigured server or a missing header exists only at runtime, so only DAST catches it.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#works\">How DAST works<\/a><\/li>\n    <li><a href=\"#finds\">What DAST finds, and what it misses<\/a><\/li>\n    <li><a href=\"#sast\">DAST compared with SAST and pentesting<\/a><\/li>\n    <li><a href=\"#running\">Running DAST without breaking things<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs dynamic testing<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"works\">How DAST works<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 170\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"DAST process: crawl the application, send crafted requests, observe responses, report findings.\">\n  <defs><marker id=\"daA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker><\/defs>\n\n  <rect x=\"10\" y=\"34\" width=\"170\" height=\"84\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"95\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#4a52a8\">1. Crawl<\/text>\n  <text x=\"95\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Map every page,<\/text>\n  <text x=\"95\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">form and endpoint<\/text>\n  <line x1=\"186\" y1=\"76\" x2=\"200\" y2=\"76\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#daA)\"\/>\n\n  <rect x=\"206\" y=\"34\" width=\"170\" height=\"84\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"291\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#3a6f5d\">2. Probe<\/text>\n  <text x=\"291\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Send crafted inputs<\/text>\n  <text x=\"291\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">to each parameter<\/text>\n  <line x1=\"382\" y1=\"76\" x2=\"396\" y2=\"76\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#daA)\"\/>\n\n  <rect x=\"402\" y=\"34\" width=\"170\" height=\"84\" rx=\"14\" fill=\"#c2d9ec\"\/>\n  <text x=\"487\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#25547a\">3. Observe<\/text>\n  <text x=\"487\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Read the response<\/text>\n  <text x=\"487\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">for signs of a flaw<\/text>\n  <line x1=\"578\" y1=\"76\" x2=\"592\" y2=\"76\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#daA)\"\/>\n\n  <rect x=\"598\" y=\"34\" width=\"154\" height=\"84\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"675\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#ffffff\">4. Report<\/text>\n  <text x=\"675\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Request, response<\/text>\n  <text x=\"675\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">and reproduction<\/text>\n\n  <text x=\"380\" y=\"150\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">The scanner never sees your code. Everything it knows comes from how the application replies.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<p>Because the scanner only knows what it can reach, coverage depends on the crawl. Pages behind a login, or forms reachable only after a multi-step flow, are invisible unless the scanner is given credentials and a path in.<\/p>\n\n<h2 id=\"finds\" class=\"c-sage\">What DAST finds, and what it misses<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>DAST finds<\/th><th>DAST misses<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Injection flaws confirmed by the application&#8217;s actual response<\/td><td>Anything in code paths the crawler never reached<\/td><\/tr>\n    <tr><td>Cross-site scripting that renders in a real browser context<\/td><td>Business logic abuse, which needs a human tester<\/td><\/tr>\n    <tr><td>Missing security headers and weak TLS configuration<\/td><td>Hardcoded secrets sitting in the repository<\/td><\/tr>\n    <tr><td>Server misconfiguration and exposed admin interfaces<\/td><td>The exact line of code responsible for a finding<\/td><\/tr>\n    <tr><td>Authentication and session handling weaknesses<\/td><td>Vulnerable dependencies, which is SCA&#8217;s job<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Why DAST findings are easier to act on<\/p>\n  <p>Every result comes with the request that triggered it and the response that proved it. There is far less argument about whether a finding is real, which is the usual reason static findings sit unfixed.<\/p>\n<\/div>\n\n<h2 id=\"sast\" class=\"c-apri\">DAST compared with SAST and pentesting<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Approach<\/th><th>Sees<\/th><th>Best at<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>SAST<\/strong><\/td><td>Source code, before deployment<\/td><td>Finding insecure patterns early, pointing at the exact line<\/td><\/tr>\n    <tr><td><strong>DAST<\/strong><\/td><td>The running application, from outside<\/td><td>Confirming what is actually exploitable once deployed<\/td><\/tr>\n    <tr><td><strong>Penetration testing<\/strong><\/td><td>Everything, with a human brain<\/td><td>Chaining flaws and abusing business logic<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>They are layers rather than alternatives. SAST runs on every commit, DAST runs against a deployed environment, and a penetration test happens periodically to find what neither tool can reason about.<\/p>\n\n<h2 id=\"running\" class=\"c-plum\">Running DAST without breaking things<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Test staging, not production<\/p>\n    <p>An active scan submits real requests. Run it where creating records and triggering emails costs nothing.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Give it credentials<\/p>\n    <p>Most of an application sits behind a login. Unauthenticated scans cover the small public part only.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Scan on a release cadence<\/p>\n    <p>Full scans take time. Run them per release rather than per commit, and keep SAST on the commit path.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto runs dynamic testing<\/h2>\n\n<p>Osto&#8217;s web scanner and mobile app scanner test running applications, and the AI scanner in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> categorises findings by severity, pinpoints the affected endpoints and produces remediation and retest reports. Because dynamic testing sits in the same platform as the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a>, a confirmed finding can be read against whether that path is already protected at the edge, which changes how urgently it needs a code fix. Expert-led <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">penetration testing<\/a> covers the logic flaws no scanner reasons about.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Test the application an attacker actually reaches<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto runs web and mobile scanning alongside expert-led VAPT, with findings read against what the WAF already blocks.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Scanner plus human testing &middot; Retest included &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does DAST stand for?<\/summary>\n  <p>Dynamic application security testing. A DAST tool tests a running application from the outside by sending crafted requests and observing the responses, without access to the source code.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between DAST and SAST?<\/summary>\n  <p>SAST analyses source code before deployment and can point at the exact line. DAST tests the deployed application and confirms what is actually reachable and exploitable. They find different classes of problem, so most teams run both.<\/p>\n<\/details>\n\n<details>\n  <summary>Can DAST replace a penetration test?<\/summary>\n  <p>No. DAST is automated and finds known vulnerability classes reliably. A penetration test adds a human who chains findings together and abuses business logic, which no scanner reasons about. Auditors and enterprise buyers ask for the test, not the scan.<\/p>\n<\/details>\n\n<details>\n  <summary>Should DAST run against production?<\/summary>\n  <p>Prefer a staging environment that mirrors production. Active scanning submits real requests, which can create records, send notifications or trigger workflows. If production is the only option, use a passive or read-only scan profile.<\/p>\n<\/details>\n\n<details>\n  <summary>Do compliance frameworks require DAST?<\/summary>\n  <p>None name the tool. ISO 27001:2022 covers security testing in development under Annex A 8.29, and SOC 2 auditors expect <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-evidence-collection\/\" target=\"_blank\" rel=\"noopener\">evidence that applications are tested<\/a> before release. DAST output is one accepted form of that evidence.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> SAST &middot; Penetration Testing &middot; Vulnerability Scanning &middot; API Security &middot; WAF &middot; VAPT<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>DAST tests a running application from the outside, sending real requests the way an attacker would, to find weaknesses that\u2026<\/p>\n","protected":false},"author":8,"featured_media":677,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[255,257,256],"class_list":["post-676","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-dast","tag-dast-vs-sast","tag-what-is-dast"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/676","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=676"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/676\/revisions"}],"predecessor-version":[{"id":678,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/676\/revisions\/678"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/677"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=676"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=676"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=676"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}