GraphQL Voyager: Visualize any GraphQL API as an interactive graph, aiding in understanding and exploration of its schema and relationships.
GraphQLmap is a scripting engine for GraphQL endpoint pentesting, automating queries and fuzzing for vulnerabilities.
InQL is a Burp Suite extension for advanced GraphQL testing, offering vulnerability detection and customizable scans.
Interactsh is a tool and service for capturing and handling out-of-band interactions during security testing.
JWT Debugger is a web application to create, encode, decode, and debug JWT (JSON Web Tokens).
Kiterunner is a contextual content discovery tool for modern web applications and APIs, excelling in route/endpoint bruteforcing.
LeakInsight API is a data leak detection service that helps developers and businesses identify leaked credentials and security risks across a vast database.
A comprehensive collection of payloads and bypasses for web application security testing and exploitation.
Postman: The leading API platform for building and using APIs. Streamline collaboration and simplify the API lifecycle.
Prism is an open-source HTTP mock and proxy server that accelerates API development with realistic mock servers powered by OpenAPI documents.
RESTler is a stateful REST API fuzzing tool for automatically testing cloud services and finding security and reliability bugs.
Shodan is a search engine for Internet-connected devices, enabling users to discover and monitor exposed services and gain Internet intelligence.