API and MCP security scanner

Point it at an endpoint and see what it gives away to a stranger: transport, authentication, CORS, rate limiting, error disclosure and, on an MCP server, which tools answer with no credentials at all.

Read-only. No signup.
Try

What an API security scan sees that you cannot

This free check shows what an anonymous visitor can see and do against your API security posture with no credentials and no signup. It is read-only and makes about twenty requests, sent one at a time. It checks seven areas: transport, authentication, CORS, response headers, rate limiting, error disclosure and MCP. Every check is a request any client on the internet could already make. It is not a penetration test: it does not fuzz, enumerate, brute force or send any payload designed to break anything.

The most serious gaps stay invisible from inside because inside you are always authenticated. An outside view catches what you never see while logged in. You get a grade from A+ to F and each finding comes with a written instruction that fixes exactly that finding, which can be pasted into an AI coding agent.

When to run it

  • Before you publish: Run the scan on a staging or public endpoint to catch open transport or authentication gaps before users and agents see them.
  • After an upgrade: Run it again after a framework or gateway upgrade changes defaults for CORS, headers or rate limiting.
  • Before you depend on someone else: Check an external API or MCP server you plan to integrate so you know what an anonymous client can already do.
  • Before an agent gets keys: Confirm what happens when an AI agent calls your tools without a human watching, especially if any tool writes, deletes, sends, pays or deploys.

MCP server security is a different question

An MCP server exists to let an AI agent take actions, so an open one is not just a data leak. It is a stranger holding your tools. That risk needs its own checks.

The scan sends the same JSON-RPC initialize handshake every MCP client sends when it connects. If that handshake succeeds without credentials it then asks for the tool list. It never calls a tool because calling one would run code on someone else's system. A tool whose name suggests it writes, deletes, sends, pays or deploys is treated as more serious when it is reachable without credentials. A read-only MCP server that answers anonymously on purpose is noted as such and not graded as a flaw.

We track 30 MCP servers in our directory and have run 109,396 outside-in agent readiness scans with the same method, which is where the MCP detection here comes from: a server card, or a live Streamable HTTP endpoint that answers an initialize handshake.

What this scan deliberately does not do

The scan is deliberately limited. It only does what any anonymous client on the internet could already do. It is read-only and makes about twenty requests, sent one at a time, across seven areas: transport, authentication, CORS, response headers, rate limiting, error disclosure and MCP. It is not a penetration test: it does not fuzz, enumerate, brute force or send any payload designed to break anything.

That limit is the point when the target belongs to someone else. On an MCP server it sends a JSON-RPC initialize handshake and asks for the tool list if that succeeds without credentials, but it never calls a tool because calling one would run code on someone else's system.

Frequently asked questions

What does the API security scanner check?
It checks seven areas: transport, authentication, CORS, response headers, rate limiting, error disclosure and MCP. You get a grade from A+ to F and each finding comes with a written instruction that fixes exactly that finding, which can be pasted into an AI coding agent. The scan is read-only and makes about twenty requests, sent one at a time.
Is the scan safe to run against a production endpoint?
Yes. The scan is safe for production because it is read-only and makes about twenty requests, sent one at a time. It does not fuzz, enumerate, brute force or send any payload designed to break anything. It is not a penetration test and every check is a request any client on the internet could already make. The twenty requests are a small load but they are real requests.
Can I scan an MCP server?
Yes. On an MCP server the scan sends the same JSON-RPC initialize handshake every MCP client sends when it connects. If that handshake succeeds without credentials it then asks for the tool list. It never calls a tool because calling one would run code on someone else's system. A tool whose name suggests it writes, deletes, sends, pays or deploys and is reachable without credentials is treated as the most serious finding.
Do I need to sign in or give you an API key?
No. You do not need to sign in or provide an API key. The scan needs no credentials and no signup because it shows only what an anonymous stranger on the internet can already see and do.
My API returns data without a key and the scan flagged it. Is that wrong?
No, it is not necessarily wrong. A public API is allowed to return data without a key and the scan cannot know your intent so it asks rather than fails. If the response contains no personal or secret fields it is shown as a question to confirm. If the body contains fields such as an email address or a token it is treated as a real finding.
What does the grade mean?
The grade from A+ to F is a weighted ratio of the checks that could actually be scored. It covers seven areas including transport, authentication, CORS, response headers, rate limiting, error disclosure and MCP. Checks that cannot be measured from outside are shown but not scored so a correctly locked API is not punished for being locked.

Related tools