API inventory

You cannot secure, monitor or retire an API you do not know exists.

Undocumented endpoints accumulate: internal ones that became public, test versions left running, things added during an incident. They receive no scanning, no gateway policy and no attention. Discovering them from traffic rather than from documentation is usually the only way to find out what you actually run.

Checked against the primary source.

More on API security