
API-Security-Checklist
Checklist of the most important security countermeasures when designing, testing, and releasing your API
API key scanning, credential leak detection, and secret management tools.

Checklist of the most important security countermeasures when designing, testing, and releasing your API

A tool for secrets management, encryption as a service, and privileged access management

Find, verify, and analyze leaked credentials

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Simple and flexible tool for managing secrets

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Incredibly fast crawler designed for OSINT.

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

Snyk CLI scans and monitors your projects for security vulnerabilities.

OpenSSF Scorecard - Security health metrics for Open Source