# API-Security/APIKit

APIKit：Discovery, Scan and Audit APIs Toolkit All In One.

Repository: https://github.com/API-Security/APIKit
Canonical: https://ross.abutalabs.com/products/apikit
Language: Java
License: GPL-3.0
License Family: copyleft
Topics: burp-extensions, apisec, api-security, api-sec
Last push: 2024-04-02T09:29:56+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1743, "days_push": 883, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2286, forks 179 (observed 2026-08-28T04:06:34.635445+00:00)

## What it is
APIKit is a BurpSuite extension (Java plugin) that discovers, scans, and audits leaked API documentation such as GraphQL, OpenAPI/Swagger, Spring Boot Actuator, SOAP/WSDL, and REST/WADL. It parses discovered API docs into BurpSuite requests for API security testing and can automate unauthorized-access checks.

## Use cases
- discover leaked swagger or graphql endpoints in burp traffic
- find exposed spring boot actuator endpoints during pentests
- parse api documentation into replayable burp requests
- automate testing for api unauthorized access vulnerabilities
- chain apikit with xray for full api vulnerability scanning
- fingerprint api technologies on arbitrary targets

## When to choose
- you already use BurpSuite for web/API penetration testing
- you need passive discovery of API docs from live traffic
- you want to detect exposed actuator, swagger, or WSDL endpoints during authorized assessments

## When to avoid
- you need a standalone scanner outside BurpSuite
- you lack authorization to test the target
- you need non-Java/Burp environments or CI-based API scanning

## Facets
- artifact type: plugin
- maturity: active
- function: security, penetration-testing, vulnerability-scanning, parser
- domain: security, apis, penetration-testing, developer-tools
- platform: jvm
- tags: burp-extension, api-security, api-discovery, swagger, graphql, openapi, passive-scanning, unauthorized-access, burpsuite

## Member repositories
- API-Security/APIKit (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:34.635445+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:40:53.174363+00:00, confidence not recorded.
  - readme: https://github.com/API-Security/APIKit (fetched 2026-08-28T04:06:34.635445+00:00, sha 982cbc6aaaf6)
- Data as of 2026-08-30T08:39:29.467469+00:00.
