Tutorials

API Security Audit using OpenAPI Swagger Editor Extension in VS Code

Identify and fix issues in the OpenAPI (formerly Swagger) definition file using the API Audit, available via the OpenAPI Editor in Microsoft Visual Studio Code (VS Code).

Reviewing The Score

API audit runs over 300 different checks and provides an overall score that represents the quality of your OpenAPI definition. Learn more by viewing the explanatory video.

Filtering The Audit Report

There are a number of ways to filter the results from the audit report. More in details in the video.

Auditing API Operations

For each operation in your OpenAPI file you have the ability to run the audit just on that single operation.

Fixing Audit Issues

How to work through the Audit report to fix identified issues starting with the critical ones.

Using "Quickfix" Automations

In many cases you will see the option to use a "Quickfix" for identified issues. This is where our tool will automatically add the appropriate fields or insert a template into the OpenAPI definition. There is also a "group fix" option where all of the same issues can be fixed in one go.

Latest Resources

WEBINAR

State of API Security 2026

Webinar drawing on two years of investigative research from the industry’s leading APIsecurity.io newsletter that includes cases from a wide range of independent sources, the webinar highlights the most common API flaws, from broken input validation and missing authentication to operation-level authorization failures.

BLOG

The State of API Security Report 2026

By Hugh Carroll | February 16, 2026

The State of API Security in 2026: Analysis of real-world API vulnerabilities Our recently published State of API Security Report 2026﹡ delivers a data-driven analysis of real-world API vulnerabilities, showing how common mistakes in implementation translate into security risks in production. It paints a clear and, at times, […]

DataSheet

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Secure Your APIs Today

#1 API security platform