Every endpoint found. Every endpoint tested.
Build a live inventory of your APIs from specs, collections and real traffic, including the shadow and deprecated ones nobody documented. Then test each one for broken authorization, data exposure and the rest of the OWASP API Security Top 10.
- REST & GraphQL
- gRPC & webhooks
- Shadow API discovery
- Multi-tenant testing
- CI/CD integration
- OWASP API Top 10
api.example.com · 4 services · last synced 6 min agoAPI inventory
- 612Endpoints
- 14Shadow
- 9Deprecated
- 38Handle PII
| Method | Endpoint | Auth | Data | Source | Risk |
|---|---|---|---|---|---|
| GET | /v2/invoices/{id} | Bearer | Financial | Spec + traffic | Critical |
| PATCH | /v2/users/{id} | Bearer | PII | Spec + traffic | High |
| GET | /internal/export/customersShadow | None | PII | Traffic only | Critical |
| POST | /v1/payments/refundDeprecated | API key | Financial | Traffic only | High |
| GET | /v2/reports?tenant= | Bearer | Business | Spec | Medium |
| POST | /graphql | Bearer | Mixed | Spec + traffic | Medium |
| DELETE | /v2/projects/{id} | Bearer | Business | Spec | Medium |
| POST | /webhooks/billing | HMAC | Financial | Spec | Low |
| GET | /healthz | None | None | Traffic only | Low |
Discovery sources
- OpenAPI and Swagger specs421
- Postman collections188
- Gateway and traffic logs574
- Front-end crawl (DAST)212
CriticalAPI1:2023
Broken object-level authorizationGET /v2/invoices/{id} returns another tenant's invoice when called with a valid token from a different account. Confirmed across 3 test tenants.Sent to SEC-1182 · retest requestedYou can't secure the APIs you don't know about.
- Discover
A live inventory, built automatically.
- Import OpenAPI, Postman and GraphQL schemas
- Learn endpoints from gateway and traffic logs
- Flag undocumented, shadow and deprecated APIs
- Classify endpoints that handle sensitive data
- Test
Attacks that understand your data model.
- Authorization tests across users and tenants
- Mass assignment and excessive data exposure
- Rate limiting and resource consumption
- Authentication and token handling
- Monitor
Stay current as the API changes.
- Re-test on every spec change or deploy
- Alert when new endpoints appear
- Track drift between spec and reality
- Push findings to Jira and Slack
The OWASP API Security Top 10, tested.
REST, GraphQL, gRPC and webhooks, with multi-tenant and role-aware test cases.
- API1Broken object-level authorization
- API2Broken authentication
- API3Broken object property-level authorization
- API4Unrestricted resource consumption
- API5Broken function-level authorization
- API6Unrestricted access to sensitive business flows
- API7Server-side request forgery
- API8Security misconfiguration
- API9Improper inventory management
- API10Unsafe consumption of APIs
API security questions
- Do we need an API spec to start?
- No. Specs help, but Mockingjay can build an inventory from traffic and front-end crawling alone, then flag where specs and reality disagree.
- How do you test authorization between tenants?
- You provide test accounts in two or more tenants and roles. We replay each request across identities and flag any response that returns data it shouldn’t.
- Does traffic analysis require an agent?
- No agent is needed for spec or collection imports. For traffic discovery, connect API gateway logs (such as AWS API Gateway, Kong or Apigee), cloud load balancer and CDN logs, or upload HAR files.
- Is GraphQL supported?
- Yes. We introspect schemas where allowed, and test queries and mutations for authorization, depth and batching issues.
How many APIs do you really have?
Connect a spec or a traffic source and see your inventory, including what's undocumented, in the first session.
