Skip to main content
API-SECURITY5 MIN READ

Walk the SSRF-safe fetcher

Sequence the main design controls for an API feature that fetches user-supplied URLs.

The feature Customers paste a webhook URL. Your API fetches it to validate reachability and show metadata. The server can reach places the customer cannot. SSRF defense chain Parse -> resolve -> restrict egress -> revalidate redirects -> cap response Each layer handles a bypass the previous layer cannot reliably catch alone. Shortcut if url starts with https then fetch A hostile URL fails closed before reaching internal services. Validate the destination at every point the destination can change. 01 Scheme 02 DNS/IP 03 Redirect 04 Fresh case

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us