API Security
Finding and fixing broken authorization, business-logic flaws, and identity weaknesses in modern APIs.
Developer Advocate, API Security Specialist, Agentic AI Security researcher, and cybersecurity professional.



WHAT I DO
Finding and fixing broken authorization, business-logic flaws, and identity weaknesses in modern APIs.
Researching prompt injection, unsafe tool use, excessive agency, and security boundaries for AI agents.
Making complex technical ideas useful through writing, workshops, and developer communities.
FEATURED PROJECTS
A local-first static application security testing tool with OWASP API Top 10 rules, OpenAPI analysis, SARIF reporting, and secure CI release evidence.
View project Secure code review trainingAn open-source training platform for identifying and remediating vulnerable web, API, AI, and MCP code through realistic review challenges.
View project API testing and security labPostman and Newman automation with mock environments, CI reporting, and a localhost-only service for comparing secure and vulnerable API behavior.
View project Chrome extensionPassive API reconnaissance with endpoint discovery, request analysis, findings export, and a built-in request tester.
View projectFOUNDER & COMMUNITY LEAD - APICON TANZANIA
I founded APICon Tanzania to advance API Security, DevSecOps, software engineering, and practical collaboration across the regional developer ecosystem.
Read my storyTOOLBOX
LATEST WRITING
A practical guide to selecting SDKs, APIs, frameworks, and development tools for secure, maintainable systems.
Embedding security into the software lifecycle without turning it into ceremony.
Identity, policy, transport, and telemetry for every API request.
LET’S CONNECT