Tool · api-securityhostedopt-in
Akto
Open-source API-security platform with a large BOLA/IDOR/broken-auth test library, usable as an independent authorization cross-check.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
A shared, hosted instance — for practice only, within the platform's own rules.
Tagsapi-security
More tools
- BurpAPISecuritySuiteapi-securityA Burp Suite extension for API security testing that auto-captures and normalizes API traffic, groups endpoints, and generates fuzzing campaigns covering OWASP API Top 10 issues (BOLA/IDOR, SQLi, XSS, NoSQLi, XXE, JWT abuse, GraphQL abuse, race conditions). It exports to Burp Intruder/Turbo Intruder, Nuclei, and external tools (SQLMap, Dalfox, HTTPX, Katana, FFUF), and is actively maintained (v1.4.15, MIT).
- EvoMasterapi-securityState-of-the-art REST API fuzzer with a dedicated authorization SECURITY phase that flags access-control faults from two authenticated users.
- GraphQLerapi-securityDependency-aware GraphQL security tester that builds the query/mutation graph and runs two-profile cross-user IDOR/BOLA checks.
- Hadrianapi-securityPraetorian's headless OWASP-API authorization scanner covering BOLA, BFLA, OTP-brute/no-rate-limit ATO and mass-assignment with setup-attack-verify proof.
- agent-chaperoneagent-guardrailApache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.
- AI Vuln Scannerdast/web-app-scannerA security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.