API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven templates
-
Updated
Aug 10, 2026 - Go
API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven templates
Burp Suite extension for authorization testing in Java serialized communication: decode, inspect, and edit serialized objects live
Authorization testing for MCP servers; works on HTTP APIs too. Turns an access-control matrix into positive & negative tests that catch BOLA, BFLA, BOPLA, privilege escalation, token-audience and session-binding flaws across tools and resources — with CWE/OWASP-tagged SARIF for CI/CD.
ReqEye is a CLI assistant for HTTP request analysis, designed to help security researchers, bug bounty hunters, and pentesters identify high‑value entry points worth manual testing. It does not scan targets, send traffic, or claim vulnerabilities. ReqEye focuses on where to look, not on making assumptions.
A tool that detects unauthorized access vulnerabilities through passive proxies, leveraging mainstream AI systems such as Kimi, DeepSeek, GPT, and others,vulnerabilities, privilege-escalation, authorization-bypass, detects-access
3-stage authorized security pipeline: CDP mapper, multi-actor permission matrix, and automated PoC generation
A tool that detects unauthorized access vulnerabilities through passive proxies, leveraging mainstream AI systems such as Kimi, DeepSeek, GPT, and others,vulnerabilities, privilege-escalation, authorization-bypass, detects-access
MCP server for autonomous API logic penetration testing. AI-driven detection of OWASP API Top 10 vulnerabilities (BOLA/IDOR) via multi-session authorization comparison. Supports Bearer, Basic, API Key, Cookie auth. Generates Markdown security audit reports with evidence.
State-aware Burp Suite extension for mutating multi-step workflows and detecting business-logic flaws with probes, invariants, isolated actors, and cleanup.
Add a description, image, and links to the authorization-testing topic page so that developers can more easily learn about it.
To associate your repository with the authorization-testing topic, visit your repo's landing page and select "manage topics."