NEWS

APIsecurity.io adds API Security issues and a free API Contract Security Audit service

LONDON, UK, February 13, 2019 — API Contract Security Audit is a free online tool that lets developers and security professionals upload their OpenAPI definition files and get a detailed security assessment on the potential risks that their APIs might have. Each issue in the report shows the specific place in the API contract that may cause trouble, provides details on the potential exploit scenario, and shows recommendations on how to improve the API definition to mitigate the risk.

“There is much talk recently about “shifting left” in security – to start vulnerability testing at an earlier stage of the development lifecycle. With the OpenAPI Contract Audit tool from 42Crunch, you can test your API even before it’s been created, quickly investigating potential security issues and getting actionable recommendations for fixing them. Can you go more left than that?” says Alexei Balaganski, Lead Analyst at KuppingerCole Analysts AG.

API Security Encyclopedia is a free online resource with almost 200 articles on potential API security risks, possible exploit scenarios, and recommendations on how to mitigate the risks.

Alexei Balaganski adds: “Perhaps the biggest obstacle for companies towards adopting API security best practices is not knowing they are doing something wrong at all. What they need is a clear and concise guide outlining typical API-related anti-patterns, demonstrating their security risks and offering proven methods of mitigating them. 42crunch’s recently launched API Security Encyclopedia is exactly that and already shows great potential for all API developers”.

“42Crunch launched APIsecurity.io in October 2018,” says Dmitry Sotnikov, VP of Cloud Platform at 42Crunch. “It has become a popular source of API security news and information, with more than a thousand subscribers to its weekly newsletter. Now, we are extending the usefulness of this community site by putting some of the most valuable know-how and technology of 42Crunch on this site for the community to use. Our mission is to share knowledge with the community and help everyone make their APIs secure.”

About 42Crunch

Founded in London, UK, with offices in Dublin (Ireland), Montpellier (France) and Irvine (California), 42Crunch is known for launching the first API Firewall on the market, and provides a security platform that automatically generates and enforces risk-based security policies on enterprises’ APIs. The cloud solution addresses the most demanding API security requirements for enterprises around the world. 42Crunch API Platform also fosters the collaboration of security, development, and operations teams, and enables a DevSecOps approach to API lifecycle. Visit https://42crunch.com to learn more.

Trademarks and registered trademarks are the property of their respective owners.

Isabelle Mauny
42Crunch

Latest Resources

WEBINAR

OWASP BOLA, BA, BOPLA: wie man sie finded und behebt

Wir werden verstehen wie die OWASP API Top 3 von Hackern genutzt werden um Daten aus Unternehmen zu stehlen und wie man sie schon während der Implementierung findet und beheben kann.

BLOG

Bridging the API Security Gap – The Perception and Reality of API Security

By Hugh Carroll | June 9, 2025

What is the API Security Gap? A recent report from Akamai as covered in the apisecurity.io newsletter, corroborates earlier findings from a report we commissioned of EMA Enterprise Management Associates into enterprise adoption patterns of API security technologies. Both studies indicate that while there is a broad recognition […]

DataSheet

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Secure Your APIs Today

#1 API security platform