HostedScan

Feature spotlight

API Security Scanner

Security and vulnerability testing for APIs

HostedScan dashboard showing API security scan results, health score, and detected risks

what it is

API Security Scan vs Traditional Website Scan

An API vulnerability scan tests API routes for security issues, such as SQL injection and remote command execution (RCE). To understand the API routes and parameters, the scanner reads an API definition file, such as an OpenAPI or Swagger template.

This is different from a traditional website scanner, which starts from a website URL and crawls the webpage by following hyperlinks and clicking buttons. While a website scan may discover some APIs while crawling, it will likely be less complete than a scan of the full API definition. However, a traditional website scan will also inspect the website's HTML and JavaScript for security issues, such as a vulnerable JavaScript dependency.

how it works

How to set up API security scanning

With HostedScan Security you can import an OpenAPI definition file and scan your API with the OWASP ZAP scanner.

Follow the steps below to set up an API vulnerability scan:

  1. 01

    Click the Add Targets button.

    HostedScan Targets page with the Add Targets button highlighted
  2. 02

    Click the Import from OpenAPI button at the bottom of the dialog.

    Add Targets dialog showing the available import integrations
  3. 03

    Upload your OpenAPI definition file (JSON or YAML format), set the base URL, and include headers for authentication (if required).

    You can configure authentication by setting a Header Key and Header Value with appropriate API keys.

    Import from OpenAPI form with fields for the definition file, base URL, and authentication headers
  4. 04

    Create a scan for the newly created target.

    Targets list with the newly created API target
  5. 05

    Run an OWASP ZAP Active scan on the new target.

    New Scan dialog with the OWASP ZAP Active scan option selected
  6. 06

    Finally, configure your scan to either run once or on a recurring schedule, and choose your preferred notification settings.

    This scan will send payloads to your API routes

    Scan scheduling and notification settings

Our Customers

5,000+ MSPs and IT teams who move faster

BbAmericas
Porsche
ExpediaGroup
WeMakeApps
SibylSoft
Luminary
CoinMe
Appetize
WonderProxy
Median
TaxiCaller
Yamaha
UniversityOfOxford

Speed and power,
without the complexity

The world's leading vulnerability scanners, all in one platform.

Loading call to action