Skip to content
S
SnapUtilsPro
API & DevOps

API Security Scanner (Heuristics)

Paste an OpenAPI or JSON API spec to flag common smells: missing auth, empty security arrays, sensitive paths, and HTTP servers. Results are guidance only — this tool does not send requests, exploit APIs, or replace a professional assessment.

Runs entirely in your browser. Your data never leaves this device.

  • Static OpenAPI heuristics
  • Auth and path smell checks
  • No network scanning
  • Not a penetration test
  • Local analysis only
Workspace
Client-side · No upload

How it works

  1. Paste an OpenAPI/JSON spec you are authorized to review.
  2. Run heuristic checks for missing auth, sensitive paths, and HTTP URLs.
  3. Treat results as guidance — not a pentest, exploit kit, or authorization to scan live hosts.

Key features

  • Static OpenAPI heuristics
  • Auth and path smell checks
  • No network scanning
  • Not a penetration test
  • Local analysis only

FAQ

Is this a pentest tool?

No. It only runs static heuristics on specs you paste. It does not discover hosts or send probes.

Does it attack my API?

No network scanning or exploitation is performed. Analysis stays in your browser.

Can I use this on third-party APIs?

Only review specifications you own or have permission to assess. Do not use findings to attack systems without consent.

How to use results?

Treat findings as review prompts for your security process alongside professional testing.

Related developer tools