APIClarity logo

APIClarity

APIClarity is an open source API security and observability tool that analyzes API traffic to reconstruct OpenAPI specifications, detect shadow and zombie APIs, identify API differences and changes, and provide API security alerts. It is part of the OpenClarity project and works with Kubernetes service meshes and API gateways for cloud-native API traffic observability.

1 APIs 7 Features
API ObservabilityAPI SecurityAPI Traffic AnalysisCiscoKubernetesOpen SourceOpenAPI ReconstructionOpenClarityService MeshShadow APIs

APIs

APIClarity API

The APIClarity API provides programmatic access to API traffic analysis, reconstructed OpenAPI specifications, API inventory, and security findings. It allows users to query dis...

Features

OpenAPI Spec Reconstruction

Automatically reconstruct OpenAPI specifications from observed live API traffic without code instrumentation.

Shadow API Detection

Identify undocumented shadow APIs being called in production that are not reflected in official specifications.

Zombie API Detection

Detect deprecated or decommissioned API endpoints still receiving traffic in production.

API Diff Analysis

Compare observed API behavior against documented specifications to identify drifts, changes, and violations.

API Security Alerts

Generate security findings and alerts based on API traffic analysis and specification violations.

Kubernetes Integration

Deploy as a sidecar or via Helm charts for integration with Kubernetes service meshes and API gateways.

API Inventory

Automatically build and maintain an inventory of all APIs discovered in the environment.

Use Cases

API Discovery

Discover all APIs running in a Kubernetes environment including undocumented and shadow APIs.

API Security Posture Assessment

Assess API security by detecting shadow APIs, spec violations, and suspicious traffic patterns.

API Specification Generation

Generate OpenAPI specifications from live traffic for APIs that lack formal documentation.

API Governance

Enforce API consistency by detecting deviations between actual API behavior and official specifications.

Incident Response

Investigate API security incidents using traffic analysis, API inventory, and spec diff data.

Resources

🔗
Website
Website
👥
GitHubOrganization
GitHubOrganization
👥
GitHubRepository
GitHubRepository
🔗
Documentation
Documentation
🔗
Issues
Issues
📄
Releases
Releases
🔗
License
License
🔗
Slack
Slack