nowfound

Dev tools · February 14, 2023

OS

Openapi.security, a fast security checker for REST-based API

tl;dr we released openapi.security, an online tool that performs a dozen of security tests on any given openapi/swagger-based API, with no signup or email required. You can try it here: https://openapi.security My team at Escape (YC W23) is mainly focused on securing GraphQL APIs. For this, we developed a new approach called Feedback driven API Exploration. Basically, we infer the right security tests cases to run using the specification and a carefully crafted in house graph traversal algorithm. (It's a bit long to describe here but we published a more in depth explanation of…

In plain words

Openapi.security is an online tool that runs a dozen security tests on REST APIs defined with OpenAPI or Swagger specifications. It requires no signup or email and works directly from an API specification. The tool uses feedback-driven API exploration with graph traversal algorithms to identify and execute relevant security test cases automatically. It is designed for developers and security teams who need to quickly assess the security posture of REST-based APIs.

written from the facts on this page · September 2026

From the sources

In the maker’s words, at launch

tl;dr we released openapi.security, an online tool that performs a dozen of security tests on any given openapi/swagger-based API, with no signup or email required. You can try it here: https://openapi.security My team at Escape (YC W23) is mainly focused on securing GraphQL APIs. For this, we developed a new approach called Feedback driven API Exploration. Basically, we infer the right security tests cases to run using the specification and a carefully crafted in house graph traversal algorithm. (It's a bit long to describe here but we published a more in depth explanation of how this algorithm works in our blog!) We recently wondered if this Feedback Driven Exploration approach could be efficiently applied to good old REST APIs as well. From our experience, well designed GraphQL and REST APIs are quite equivalent: both have an organized data structure and explicit relationships between objects. So why wouldn't it work? We often organise internal hackathons. So this time, we focused on this experiment, adapting our algorithm to REST and ending up creating our last side project: OpenAPI.security. It is a very simple tool: anybody can enter an OpenAPI / Swagger spec, and openapi.security will run a bunch of security tests on it and give back a report. It's designed to be fast and smart in the way it analyzes input specs.

More dev tools this month

the category →
  • Dograh592

    The open source VAPI alternative

    Dev tools · 25d ago · dograh.com

  • Meridian530

    Don't let your work go unnoticed. Get promoted!

    Dev tools · 20d ago · meridiona.com

  • x1516

    Lovable for iPhone apps go from idea to App Store

    Dev tools · 11d ago · x1.new

  • Open-source GTM skills for technical founders

    Dev tools · 29d ago · gtmcofounder.com

  • OpenTrailPaper is open-source bike computer firmware for the LilyGO T5S3 4.7" E-Paper PRO. It supports offline maps, GPX routes, FIT recording and Bluetooth sensors.

    Dev tools · 1d ago · opentrailpaper.com

  • Nuphos380

    The AI-Native DevOps Workspace.

    Dev tools · 24d ago · nuphos.ai

Launched alongside, February 2023

the whole month →
  • Bento1,373

    A link in bio, but rich and beautiful

    Dev tools · 2023 · linktr.ee

  • Jitter 1.01,020

    A fast and simple animation tool on the web 💫

    Work · 2023 · jitter.video

  • Twinr 2.0961

    Convert any website to mobile apps in minutes

    Dev tools · 2023 · twinr.dev

  • Your on-demand presentation generator

    AI · 2023 · decktopus.com

  • Aaply812

    Make your mobile app happen

    Dev tools · 2023 · aaply.app

  • Scalenut783

    AI that powers your entire content lifecycle

    AI · 2023 · scalenut.com