ONYX · API SECURITY TESTING

    Break your{ }APIbefore they do.

    Onyx reads your OpenAPI spec, generates schema-aware attack payloads, and streams every result back live.

    8Attack categories
    400+Payloads / run
    OpenAPI · SwaggerSpec formats

    Built on the tools security teams already trust

    • Google GeminiGoogle Gemini
    • OpenAPIOpenAPI
    • RedisRedis
    • PostgreSQLPostgreSQL
    • ReactReact
    • VercelVercel
    • TypeScriptTypeScript
    • ExpressExpress
    • Google GeminiGoogle Gemini
    • OpenAPIOpenAPI
    • RedisRedis
    • PostgreSQLPostgreSQL
    • ReactReact
    • VercelVercel
    • TypeScriptTypeScript
    • ExpressExpress
    STOP GUESSING. START BREAKING.

    Never miss a vuln

    Onyx plugs an AI attacker into your OpenAPI spec. It fires SQL injection, auth bypass, XSS, type confusion and more at every endpoint you expose.

    All{}SPECneeded wasONYX
    Attack running00 / 05
    POSTSQLISQL injection on /users?sort=, error-based leakCRIT
    GETAUTHAuth bypass on /admin, missing role checkHIGH
    PUTTYPEType confusion on /orders, array coerced to objectMED
    GETXSSReflected XSS on /search?q=, payload echoed unescapedMED
    PATCHBOLAMass assignment on /profile, is_admin writableHIGH
    8 OWASP CATEGORIES

    One spec, every attack

    From a single OpenAPI URL, Onyx probes every endpoint across 8 OWASP-mapped attack categories: injection, auth, access control, and more, all in one run.

    HOW IT WORKS

    How Onyx breaks your API

    Four steps from a spec URL to a live, severity-scored attack stream, with ownership verification built in.

    01

    Ingest

    your API schema

    Paste your OpenAPI v3 or Swagger URL. The engine parses every route, parameter, and request body automatically, with no manual setup.

    02

    Verify

    domain ownership

    Before a single request fires, prove you own the target via a file probe or DNS TXT record. SSRF guards block private and internal hosts.

    03

    Generate

    attack payloads

    Gemini 2.5 Flash crafts targeted, schema-aware payloads across 8 OWASP attack categories, tuned to each endpoint.

    04

    Fire

    and stream results

    Payloads fire through a BullMQ Redis queue, streaming back live over WebSockets, each scored by CVSS severity.

    AUTHENTICATED TESTING

    Test what’s behind the login.

    Most real API risk lives behind auth. Onyx logs in with a bearer token, API key, cookie, OAuth2 client-credentials, or a full login flow — then attacks the endpoints that actually matter. It even strips auth on purpose to prove your access controls hold.

    • Static tokens & API keysBearer, custom header, or cookie
    • OAuth2 & login flows with auto-refreshClient-credentials or a full login request
    • Encrypted at rest, never loggedAES-256-GCM; secrets stay secret
    • Missing-auth probesStrips auth to catch broken access control
    OWASP API TOP 10

    Every finding, named.

    From injection to broken authentication to resource exhaustion, every result is mapped to the OWASP API Security Top 10 (2023) — API1 through API10 — with a coverage matrix in every report and PDF export.

    Actively detected todayMapped — expanding coverage
    • API1Mapped
      Broken Object Level Authorization
    • API2Detected
      Broken Authentication
    • API3Detected
      Broken Object Property Level Authorization
    • API4Detected
      Unrestricted Resource Consumption
    • API5Mapped
      Broken Function Level Authorization
    • API6Mapped
      Unrestricted Access to Sensitive Business Flows
    • API7Mapped
      Server Side Request Forgery
    • API8Detected
      Security Misconfiguration
    • API9Mapped
      Improper Inventory Management
    • API10Mapped
      Unsafe Consumption of APIs
    SHIFT LEFT

    Break the build before attackers break in.

    Run Onyx in CI with one command or drop in our GitHub Action. Fail the PR on criticals, comment findings inline, and ship SARIF straight to your GitHub Security tab.

    • One-line CLItable / JSON / SARIF output
    • GitHub Action with PR commentsFindings commented inline on the PR
    • SARIF → GitHub Security tabAlerts land in code scanning
    • Exit-code gating for any CIFail the build on criticals
    terminal
    onyx scan --spec ./openapi.json --fail-on high --format sarif
    .github/workflows/onyx.yml
    - uses: onyx/scan-action@v1
      with:
        spec: ./openapi.json
        fail-on: high
    SEE IT WORK

    Watch it attack, live.

    Every payload streams back in real time — method, status, latency — and lands as a confirmed finding with the exact evidence and the fix. Here’s a replay.

    Product walkthroughScreen-recording of a live scan — coming soon.
    Sample reportA real severity-scored report with OWASP coverage — coming soon.
    CAPABILITIES

    Built for how you break APIs

    Every capability tuned to the way you actually test, automated and real-time, all in one run.

    AI Payload Generation

    Gemini crafts schema-aware attack payloads: SQL injection, XSS, type confusion, and auth bypass.

    Explore

    Live Attack Stream

    Watch payloads execute in real time over a WebSocket feed, streaming straight to your dashboard.

    Explore

    Real-Time Dashboard

    A command center for your runs. Track critical failures and drill into each endpoint, live.

    Explore

    Deep Detection

    Pinpoint the exact query params, headers, and bodies that trigger data leaks or crashes.

    Explore

    Detailed Reporting

    Export full PDF and JSON reports with severity classification and remediation steps.

    Explore
    MULTI-ENVIRONMENT

    Every spec, every environment

    Point Onyx at staging, then production, then a partner's sandbox, each with its own ownership proof. Run them all from one dashboard, no re-setup between targets.

    staging
    api.staging.acme.devverified
    production
    api.acme.comverified
    partner
    api.partner.ioverified
    local
    localhost:4000unverified
    MODEL-AGNOSTIC

    Swap models without re-wiring

    Your attack config lives with Onyx, not the model. The moment a sharper model ships, point to it and your specs, scopes, and history come along.

    • Gemini 2.5 Flash today, the next SOTA model tomorrow, zero re-config
    • Static fallback payloads keep runs green even if the model is down
    • Per-endpoint tuning is preserved across every model swap
    BUILT TO BE SAFE

    Peace of mind, built in

    Onyx acts on your behalf and never puts you at risk. Every run is fenced by ownership proofs, SSRF guards, and hard timeouts.

    Ownership-gated

    No payload fires until you prove you own the target via file probe or DNS TXT record.

    Never touches prod by accident

    SSRF guards block private and internal hosts; per-plan rate limits and a 10s timeout cap every job.

    Your data stays yours

    Onyx stores results scoped to your account. No one else sees your specs, payloads, or findings.

    PRICING

    Simple, transparent pricing

    Start free. Upgrade when you need more power.

    No credit card required · Cancel anytime

    Free

    $0/mo
    • 5 test runs / month
    • 10 endpoints per run
    • 5 attack types
    • Community support
    Most Popular

    Pro

    $9/mo
    Billed in INR (₹900/mo)
    • 100 test runs / month
    • 50 endpoints per run
    • All attack types
    • PDF reports
    • Priority support

    Team

    $18/mo
    Billed in INR (₹1800/mo)
    • 500 test runs / month
    • Unlimited endpoints
    • Everything in Pro
    • Multi-user workspaces
    • API access
    • SLA support
    BUILT-IN GUARDRAILS

    Aggressive on targets. Safe by design.

    Domain-ownership verification, SSRF protection, per-plan rate limiting and a hard job timeout mean Onyx only ever hits the API you actually own.

    Attack vectors per run
    0+

    Schema-aware payloads across 8 OWASP categories.

    FAQ

    Questions, answered

    Any REST API with an OpenAPI v3 or Swagger 2.0 spec. Paste the spec URL and Onyx parses every endpoint, parameter, and request body automatically.

    Your API has flaws.
    Find them first.

    View on GitHub