Kiterunner is a contextual content discovery tool for modern web applications and APIs, excelling in route/endpoint bruteforcing.
Postman: The leading API platform for building and using APIs. Streamline collaboration and simplify the API lifecycle.
Prism is an open-source HTTP mock and proxy server that accelerates API development with realistic mock servers powered by OpenAPI documents.
RESTler is a stateful REST API fuzzing tool for automatically testing cloud services and finding security and reliability bugs.
WuppieFuzz: coverage-guided REST API fuzzer using LibAFL, easy-to-use, explainable flaws, modular, supports black/grey/white box testing.
crAPI is a completely ridiculous API vulnerable by design, built on a microservices architecture, designed to help understand API security risks.
GraphQL Server Engine Fingerprinting utility for software security professionals.