Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.
-
Updated
Jul 19, 2026 - JavaScript
Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.
Sniper. Passive Secrets Hunting.🚬
UZYNTRA UI is a modern control plane that provides real-time visibility, threat intelligence, and operational control over API security systems.
An open-source security analysis platform for education and vulnerability discovery.
A deliberately vulnerable FinTech web application for web application penetration testing practice.
Cloudflare worker that verifies incoming requests have a valid Approov Token. See blog post https://blog.approov.io/securing-the-api-server-with-approov-and-cloudflare.
A smart honeypot & security gateway for OpenWebUI, powered by Cloudflare Workers. Blocks bots, prevents token waste, and protects your service.
Secure API Proxy Server for protecting AI API keys from client-side exposure. Supports OpenAI, Gemini, Claude, and more.
The tests demonstrate all 9 common CORS misconfigurations actively: Wildcard origins Origin reflection with credentials Null origin trust Regex bypasses (prefix/suffix) Subdomain trust pivots Preflight caching issues Unsafe methods exposure Private Network Access misconfigs
An Appoov token integration example for NodeJS. Article: https://blog.approov.io/approov-integration-in-a-nodejs-express-api
Javascript GraphQL and REST API Encryption API
Defensive AI security audit skill for Claude and Codex. Reviews codebases and web apps for OWASP Top 10, auth and authorization flaws, business logic bugs, tenant isolation gaps, insecure defaults, secret leaks, and ORM or N+1 query issues, then produces clear remediation guidance.
Educational Express API security lab: response filtering, role-based authorization, owner checks, mass-assignment protection, OpenAPI, Postman, and automated tests.
Automated API security scanning platform with OWASP API Top 10 detection, CVSS scoring, ML severity prediction, MFA, alerts, dashboard, and PDF reporting.
API Gateway for securing API Keys
Secure api by RSA sign and verify functionality
Laboratório de Engenharia de Qualidade com foco em segurança para uma API REST transacional, com modelagem de ameaças e testes negativos executáveis.
Tool-independent repository audit framework — guides any AI coding agent (Codex, Claude Code, Cursor, Gemini CLI) through a deterministic-first security & code review, with in-house + external scanners and SARIF/JSON/Markdown reports.
Backend server for Vogue Vista, handling user authentication, data management, and server-side logic. Built with Node.js/Express, PostgreSQL, and hosted on Heroku.
To associate your repository with the api-security topic, visit your repo's landing page and select "manage topics."