vAPI - Vulnerable Adversely Programmed Interface
vAPI (Vulnerable Adversely Programmed Interface) is an open-source PHP-based lab that you can use to see OWASP API Security Top 10 vulnerabilities in action. You can set it up yourself, or use a Docker image. There is also a Postman collection file documenting the API calls.