API Security
Test Plan Builder
Turn your API characteristics into a structured manual testing checklist. Plan authorization, authentication, input handling and abuse-control checks before you start.
This tool runs no tests and makes no requests to API targets. Selections stay in this page’s memory: they are not uploaded, logged or saved. Copy and download happen only when you choose them. Do not enter credentials, tokens or secrets.
Your testing plan
Every check starts as Not tested. Execute checks only in an authorized environment.
Your plan will appear here
Select an API type and authentication method, then generate a plan. Review its assumptions before using it.
Put the plan into practice
Read the API security tutorial on BOLA and mass assignment and the IDOR and broken access control tutorial. Guided Academy labs require sign-in and may have plan requirements.
PhantomRed product actions require sign-in where applicable. This plan does not configure or start a scan; validate manual API logic checks separately.
What should an API security test plan cover?
Start with scope and a valid baseline. Compare object and operation permissions, check writable properties, validate authentication and input rules, then review throttling and error responses. Record evidence and expected behavior for every executed check.
Does generating a plan find vulnerabilities?
No. The output is a checklist based on selected characteristics. It has no connection to your API and cannot verify a vulnerability or certify security.
Can I use it without an account?
Yes. Generating, copying and exporting Markdown are free and require no registration. Reloading clears the generated plan; downloaded files and clipboard content are under your control.