APIsec BOLT
12 ratings
)


Overview
Discover APIs from browser traffic and auto-generate OpenAPI specs.
APIsec BOLT discovers APIs from real browser traffic and turns them into scan-ready applications on APIsec — without proxies, agents, or manual spec writing. Browse the app normally while BOLT passively captures API calls from your active tab. It identifies endpoints, parameters, and auth tokens, then generates accurate OpenAPI Specs you can export or send directly to APIsec for automated security testing. ⸻ Key Capabilities 1. Passive API capture from the browser Capture API traffic directly from your active browser tab. No proxy setup or traffic redirection required. 2. Automatic API discovery and inventory BOLT analyzes captured traffic to identify methods, paths, parameters, hostnames, and request/response metadata — building a reliable API inventory from how your application actually behaves. 3. Single-host discovery Traffic from one application stays grouped as one API with all endpoints included — nothing dropped by over-aggressive clustering. 4. Auth token detection BOLT automatically detects and catalogs auth from captured traffic — JWT, API keys, Basic auth, Bearer tokens, and cookies — so you know what credentials your session is using. 5. Auth-aware onboarding and scans When you onboard to APIsec, BOLT registers captured login flows and triggers authenticated security scans. Supports Basic, Bearer, API key, OAuth2, and multi-step login flows. If BOLT can't build a durable auth recipe, it still runs a one-shot authenticated scan using the captured token. 6. Flexible sign-in Sign in with email/password, Google (company Workspace account required), or an APIsec API key (PAT). Onboarding and exporting work the same regardless of how you authenticate. 7. Custom application names Rename the auto-generated application name before onboarding to keep your APIsec workspace organized. 8. OpenAPI (Swagger) generation and export BOLT converts captured API calls into structured OpenAPI definitions. Exported specs use proper path parameters 9. Resilient onboarding If onboarding fails, retry after signing in again or updating your API key. Your captured traffic is preserved — you can also download the OpenAPI spec at any time. 10. Real-time security signals (during capture) As traffic is captured, BOLT can surface BOLA, RBAC misconfiguration, and Mass Assignment indicators to help you prioritize what to test next. ⸻ How It Works 1. Open a web application and launch APIsec BOLT from the Chrome toolbar. 2. Start capture to collect API traffic from your active browser tab. 3. Browse the app normally — BOLT builds your API inventory as you go. 4. Review discovered endpoints and captured auth tokens. 5. Name your application, then onboard to APIsec — authenticated scans start automatically when auth is detected. 6. Or download an OpenAPI spec to use in documentation or other security workflows. ⸻ Focused, streamlined experience BOLT is scoped to one clear job: turn an undocumented API into a scan-ready app on APIsec. Flow stays simple: capture → discover → onboard → scan. ⸻ Non-intrusive and privacy-respecting by design APIsec BOLT operates on your local machine. The browser extension handles traffic capture, API identification, and OpenAPI generation locally. BOLT does not intercept, modify, or block network traffic — it passively observes requests from the active tab. Data is sent to APIsec only when you explicitly onboard an application or export a spec. No data leaves your browser without your action. ⸻ What's New in v2.2.0 Authentication & onboarding • Sign in with Google — log in or create an account from Bolt using your Google Workspace email. • Automatic sign-in — after Google sign-up completes in the portal, Bolt signs you in without an extra step. • API key auth — sign in with an APIsec API key (PAT); onboard and export work like email login. • Improved capture and onboarding for browser-based authenticated APIs. • Credential retry — if onboarding fails, try again after signing in or updating your API key. Captured traffic is preserved. Discovery & export • Single-host discovery — traffic from one app stays one API with all endpoints included. • Custom app names — rename the auto-generated application name before onboarding. • Download OAS — exported specs use proper path parameters like ({ApplicationId}, {InstancesId}), not hardcoded UUIDs. Auth-aware security testing • Captured login registers on the platform and triggers authenticated scans (Basic, Bearer, API key, OAuth2, and multi-step login flows). If it doesn't capture a login, BOLT still runs a one-shot scan with the captured token. UI • Simpler, focused UI. BOLT is clearly scoped to one job: turn an undocumented API into a scan-ready app.
5 out of 512 ratings
Details
- Version2.2.0
- UpdatedSeptember 23, 2026
- Offered bydeveloper
- Size558KiB
- LanguagesEnglish (United States)
- DeveloperAPIsec.ai
1 Sansome St #3500 San Francisco, CA 94104-4436 USEmail
developer@apisec.aiPhone
+1 415-505-3007 - TraderThis developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
- D-U-N-S081059564
Privacy
APIsec BOLT has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
APIsec BOLT handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site