Skip to content
Mockingjay

Every endpoint found. Every endpoint tested.

Build a live inventory of your APIs from specs, collections and real traffic, including the shadow and deprecated ones nobody documented. Then test each one for broken authorization, data exposure and the rest of the OWASP API Security Top 10.

api.example.com · 4 services · last synced 6 min agoAPI inventory
  • 612Endpoints
  • 14Shadow
  • 9Deprecated
  • 38Handle PII
MethodEndpointAuthDataSourceRisk
GET/v2/invoices/{id}BearerFinancialSpec + trafficCritical
PATCH/v2/users/{id}BearerPIISpec + trafficHigh
GET/internal/export/customersShadowNonePIITraffic onlyCritical
POST/v1/payments/refundDeprecatedAPI keyFinancialTraffic onlyHigh
GET/v2/reports?tenant=BearerBusinessSpecMedium
POST/graphqlBearerMixedSpec + trafficMedium
DELETE/v2/projects/{id}BearerBusinessSpecMedium
POST/webhooks/billingHMACFinancialSpecLow
GET/healthzNoneNoneTraffic onlyLow
Discovery sources
  • OpenAPI and Swagger specs421
  • Postman collections188
  • Gateway and traffic logs574
  • Front-end crawl (DAST)212
CriticalAPI1:2023
Broken object-level authorizationGET /v2/invoices/{id} returns another tenant's invoice when called with a valid token from a different account. Confirmed across 3 test tenants.Sent to SEC-1182 · retest requested
Illustrative product view · sample data

You can't secure the APIs you don't know about.

The OWASP API Security Top 10, tested.

REST, GraphQL, gRPC and webhooks, with multi-tenant and role-aware test cases.

  1. API1Broken object-level authorization
  2. API2Broken authentication
  3. API3Broken object property-level authorization
  4. API4Unrestricted resource consumption
  5. API5Broken function-level authorization
  6. API6Unrestricted access to sensitive business flows
  7. API7Server-side request forgery
  8. API8Security misconfiguration
  9. API9Improper inventory management
  10. API10Unsafe consumption of APIs

API security questions

Do we need an API spec to start?
No. Specs help, but Mockingjay can build an inventory from traffic and front-end crawling alone, then flag where specs and reality disagree.
How do you test authorization between tenants?
You provide test accounts in two or more tenants and roles. We replay each request across identities and flag any response that returns data it shouldn’t.
Does traffic analysis require an agent?
No agent is needed for spec or collection imports. For traffic discovery, connect API gateway logs (such as AWS API Gateway, Kong or Apigee), cloud load balancer and CDN logs, or upload HAR files.
Is GraphQL supported?
Yes. We introspect schemas where allowed, and test queries and mutations for authorization, depth and batching issues.

How many APIs do you really have?

Connect a spec or a traffic source and see your inventory, including what's undocumented, in the first session.

Book a demo