A basic overview of attacking APIs using mitmproxy by Daniel Neagaru at Ruby UnConf.
Payloads are really what you pay for when you purchase a webapp security scanner.