OWASP CRT

The OWASP Community Recognition Tool (CRT) is an automated system that verifies GitHub contributions and issues verifiable, tier-based credentials (Bronze, Silver, Gold) to valued OWASP community members.

About OWASP CRT

About The Project

The OWASP Foundation thrives on the dedication of its global community of volunteers. From code contributions and documentation to chapter leadership and event organization, these efforts are the backbone of our mission.

The OWASP Community Recognition Tool aims to create a streamlined, transparent, and automated system to formally acknowledge these valuable contributions.

Key Objectives

  • Verify: To provide a clear, verifiable link between a credential and the contributions it represents.

  • Standardize: To create a consistent and fair process for recognizing community efforts.

  • Empower: To give contributors a tangible and shareable acknowledgment of their work.

How It Works

  • Authenticate: A contributor visits crt.owasp.org and authenticates via the official GitHub OAuth application.

  • Edge Validation: A Cloudflare Worker at the edge intercepts the request, verifies the secure session, and enforces a strict rate limit.

  • Analyze & Score: A GitHub Action uses the GitHub GraphQL API to scan the requester's direct commits and merged/co-authored pull requests across public OWASP repositories. Contributions are weighted, normalized, and checked against dynamically derived thresholds to assign a Gold, Silver, or Bronze tier.

  • Issue: The resulting verified data is committed to a data branch. The contributor's certificate is instantly generated.

Certificate Tiers

To recognize different levels of commitment, we issue three distinct tiers of certificates:

  • Tier 1 (Bronze)

  • Tier 2 (Silver)

  • Tier 3 (Gold)

Project Resources

Project Leaders

Meysam Bal-afkan

EmailLinkedIn

Fatemeh Zahedi

Major Contributors

Recognizing key contributors who have made significant impact on this project.

Hamidreza Abedi nasab

Design Lead

Project Information

Incubator Project
Classification
Tool
License
MIT License
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP CRT | OWASP Foundation