Item logo image for API Security Researcher

API Security Researcher

https://ndevtk.github.io/writeups/
ExtensionPrivacy & Security5 users
Item media 5 (screenshot) for API Security Researcher
Item media 1 (screenshot) for API Security Researcher
Item media 2 (screenshot) for API Security Researcher
Item media 3 (screenshot) for API Security Researcher
Item media 4 (screenshot) for API Security Researcher
Item media 5 (screenshot) for API Security Researcher
Item media 1 (screenshot) for API Security Researcher
Item media 1 (screenshot) for API Security Researcher
Item media 2 (screenshot) for API Security Researcher
Item media 3 (screenshot) for API Security Researcher
Item media 4 (screenshot) for API Security Researcher
Item media 5 (screenshot) for API Security Researcher

Overview

API discovery, protocol reverse-engineering, JavaScript security code review, and request export.

API Security Researcher passively monitors web traffic to map APIs, decode protocols, and surface security issues — all from your browser. What it does: - Captures fetch, XHR, WebSocket, and EventSource traffic without requiring debugger or webRequest permissions - Automatically decodes Protobuf, JSPB, gRPC-Web, GraphQL, Server-Sent Events, NDJSON, Google batchexecute, and async chunked responses - Learns API schemas from observed traffic — request/response structures, URL parameters, field types, and enums - Probes for official API documentation on discovered interfaces - Performs static analysis of JavaScript bundles using Babel AST to extract API call sites, proto - field maps, and enums before requests even happen - Detects DOM XSS sinks, open redirects, prototype pollution, unsafe postMessage listeners, and other security patterns with taint tracking from user-controlled sources - Exports requests as curl, fetch, or Python snippets - Exports and imports OpenAPI 3.0.3 specs with protobuf field number round-tripping - Cross-tab request log filtering and collaborative field/parameter renaming Who it's for: Security researchers, penetration testers, bug bounty hunters, and developers who want to understand the APIs behind any website. Code can be viewed at https://github.com/NDevTK/APIClient under the GNU GPL v3 license.

Details

  • Version
    1.0.0
  • Updated
    April 5, 2026
  • Size
    489KiB
  • Languages
    English (United Kingdom)
  • Developer
    Website
    Email
    ndevtk@protonmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps