Choose a lab
Public · AppSec
Application Security Lab
Live origin behind WAF, managed rules and DDoS protection — the reference architecture of Cloudflare’s app security pipeline.
appsec-lab.santos.rwxorange.com Public · Attack targetOWASP Juice Shop
Intentionally vulnerable web shop for WAF, bot management and DDoS demonstrations — attacks are inspected at the edge, not here.
juice-shop.santos.rwxorange.com Public · APIAPI Lab & Playground
Interactive API with schema-validated endpoints, JWT auth and an echo diagnostic — built for API Shield and rate limiting demos.
api-lab.santos.rwxorange.com Zero Trust · Identity requiredZTNA Lab
Private application reached only through Cloudflare Access — identity verified at the edge, origin never publicly exposed.
ztna-lab.santos.rwxorange.com