Api Security Researcher Chrome extension icon

Api Security Researcher

📦 v1.0.0
💾 489KiB
📅 2026-04-05
View on Chrome Web Store

Chrome will indicate if you already have this installed.

Overview

API Security Researcher passively monitors web traffic to map APIs, decode protocols, and surface security issues — all from your browser.

What it does:
- Captures fetch, XHR, WebSocket, and EventSource traffic without requiring debugger or webRequest permissions
- Automatically decodes Protobuf, JSPB, gRPC-Web, GraphQL, Server-Sent Events, NDJSON, Google batchexecute, and async chunked responses
- Learns API schemas from observed traffic — request/response structures, URL parameters, field types, and enums
- Probes for official API documentation on discovered interfaces
- Performs static analysis of JavaScript bundles using Babel AST to extract API call sites, proto - field maps, and enums before requests even happen
- Detects DOM XSS sinks, open redirects, prototype pollution, unsafe postMessage listeners, and other security patterns with taint tracking from user-controlled sources
- Exports requests as curl, fetch, or Python snippets
- Exports and imports OpenAPI 3.0.3 specs with protobuf field number round-tripping
- Cross-tab request log filtering and collaborative field/parameter renaming

Who it's for:
Security researchers, penetration testers, bug bounty hunters, and developers who want to understand the APIs behind any website.

Code can be viewed at https://github.com/NDevTK/APIClient under the GNU GPL v3 license.

Tags

Make Chrome Yours/privacy developer make chrome yours/privacy

Privacy Practices

Not being sold to third parties, outside of the approved use cases
Not being used or transferred for purposes that are unrelated to the item's core functionality
Not being used or transferred to determine creditworthiness or for lending purposes

🔐 Security Analysis

This extension hasn't been security-scanned yet.

Adguard Adblocker

17M+ users
Unmatched adblock extension against advertising and pop-ups. Blocks ads on Facebook, YouTube and all other websites.
Make Chrome Yours/privacy

Ublock Origin Lite

16M+ users
An efficient content blocker. Blocks ads, trackers, miners, and more immediately upon installation.
Make Chrome Yours/privacy

uBlock Origin

15M+ users
Finally, an efficient blocker. Easy on CPU and memory.
Make Chrome Yours/privacy