SaaS & API Bug Hunt
20 product and API challenges covering permissions, workflows, integrations, data, scheduling, and regression risk.
| # | Player | Best time |
|---|---|---|
| No perfect runs yet. The first spot is open. | ||
20 pages. 20 hidden defects.
Validate role-based access control.
Check API status-code semantics.
Validate API pagination metadata.
Test API credential revocation.
Check webhook idempotency.
Check identity normalization.
Validate audit coverage.
Test scheduling conversion.
Check partial failure handling.
Validate import parsing.
Test uniqueness under concurrent requests.
Check cross-session consistency.
Compare on-screen data with exported evidence.
Test session expiration enforcement.
Test timeout/retry behavior.
Check JSON schema boundaries.
Test normalization in SaaS search.
Test authorization cache invalidation.
Check truthiness mistakes in analytics.
Find a high-impact observability bug.
Challenges unlock sequentially after you start, so the timer covers the complete level.