API Security Scanner
AI-powered REST & GraphQL security assessment
Target Configuration
Configure your API target and scan preferences
Scan Mode
Quick API Scan
~30 seconds · Endpoint discovery + Header audits
Full API Scan
~2-4 minutes · Auth controls + JWT checks + Rate limiting
Deep API Scan
~5-10 minutes · Fuzzing + Injection payloads + GraphQL checks
Custom API Scan
Select individual probes below to customize your security assessment
Free Tier Limits: 5 scans per day. High-speed concurrent scans are limited to 3 active runs.
Core API Probes
CYBERINSPECT ENGINES v1.0.4DISCOVERY
Endpoint Discovery
Maps REST/GraphQL endpoints from docs or crawling.
ENGINE
EndpointCrawler v1
INTEL
OpenAPI, Postman, Crawl
AUTH
Authentication Analyzer
Checks for broken authentication and weak JWT controls.
ENGINE
AuthProbe v2
INTEL
Broken Auth, JWT alg:none
AUTHZ
Authorization Auditor
Detects IDOR and privilege escalation vulnerabilities.
ENGINE
AccessGuard
INTEL
IDOR, BOLA, PrivEsc
THROTTLE
Rate Limit Detector
Sends burst requests to verify throttling controls.
ENGINE
BurstTest
INTEL
DDoS, 429 Burst Test
LEAKS
Token Leak Detector
Scans responses/headers for exposed API keys and JWTs.
ENGINE
LeakHunter
INTEL
API Keys, Secrets Scan
DATA
Sensitive Data Exposure
Detects exposed passwords, stack traces, and secrets.
ENGINE
DataLeakScan
INTEL
PII, DB Conn, Stack Trace
INJECTION
Injection Tester
Tests parameters for SQLi, XSS, and command injection.
ENGINE
PayloadFuzzer
INTEL
SQLi, XSS, Fuzzing
GRAPHQL
GraphQL Inspector
Checks for GraphQL introspection and query abuse.
ENGINE
GraphGuard
INTEL
Introspection, Batching
Scan History
Retrieving API scan database...