// Free diagnostic
Free automated API security diagnostic
A fast, non-intrusive automated review of a public API you own. It surfaces obvious, high-signal issues in minutes — and is deliberately shallow, so it also shows you exactly what an automated pass cannot find. That gap is where a senior-led Shura Labs engagement comes in.
What it checks
- Missing/weak security headers & TLS
- CORS misconfiguration
- Endpoints reachable without the auth the spec declares
- Verbose errors / stack-trace & version leakage
- Spec publicly exposed; dangerous methods advertised
- No visible rate limiting; static spec review
What it can't (needs a human)
- Business-logic flaws
- Broken authorization / IDOR
- Chained, multi-step exploits
- Anything requiring manual methodology
Non-intrusive by design: only normal GET/HEAD/OPTIONS requests. No fuzzing, no payloads, no data changes.
- 1 · You
- 2 · Spec
- 3 · Scope
- 4 · Run
Who are you, and what are we reviewing?
Use your work email — its domain must match the API you want reviewed (you can only scan a system you own).
Verify your email
We sent a 6-digit code to your email. Enter it to confirm the address is yours.
Add your OpenAPI/Swagger spec (optional)
With a spec we can review declared endpoints and their auth. Without one, we review the base host only. Paste it or upload a file — we never fetch it from a URL.
Confirm what we'll touch
Only these URLs, only with non-intrusive GET/HEAD/OPTIONS requests.
Diagnostic in progress…
This runs in the background. We'll email the full report to your verified address — no public links. You can close this tab.
By running this you agree it is a demonstrative, non-intrusive diagnostic. Prefer a full, senior-led engagement?Talk to us.