Security tools and references for testing REST, GraphQL, SOAP, and other APIs, covering authentication flaws, authorization bypass, rate limiting, and API-specific vulnerabilities.

AI-native SAST tool for code security, detecting vulnerabilities, secrets, IaC issues, and AI model security with actionable AI fixes.

JWT Debugger is a web application to create, encode, decode, and debug JWT (JSON Web Tokens).

Moxy is an open-source DAST tool with agentic AI for modern web application security testing and automated pentesting workflows.