⚠️Requests 1 sensitive permission ✅Recently updated
Description
APIsec BOLT automatically discovers and security-tests APIs by capturing real application traffic directly from your browser—without proxies, agents, or configuration.
As you interact with an application, BOLT identifies API endpoints, detects security vulnerabilities in real time, and provides a streamlined path to analyze and test those APIs using APIsec.ai.
BOLT converts real runtime behavior into accurate API definitions and actionable security findings, eliminating guesswork and accelerating documentation, onboarding, and security workflows.
⸻
Key Capabilities
1. Automatic capture of application traffic
BOLT captures API calls directly from your active browser tab. No proxies or traffic redirection required. Start capture and browse normally; BOLT records API interactions on the fly.
2. Real-time threat detection
As traffic is captured, BOLT automatically surfaces BOLA, RBAC misconfiguration, and Mass Assignment findings — no manual trigger needed. A live findings banner alerts you to issues as they appear, with grade badges and expandable threat details in the APIs tab.
3. Automatic identification of API endpoints
Captured traffic is analyzed to identify API methods, paths, parameters, hostnames, and request/response metadata — producing a reliable API inventory based on how your application actually behaves.
4. Auth token harvesting
BOLT automatically detects and catalogs auth tokens from captured traffic — JWT, API keys, Basic auth, and cookies — in a dedicated Auth tab. Your token inventory builds itself as you browse.
5. Request editing and replay
The Manipulator tab lets you edit and resend any captured request. A smart param picker surfaces suggestions from all captured traffic, with editable path parameters for IDOR and BOLA testing.
6. Automatic generation of OpenAPI (Swagger) specifications
BOLT converts captured API calls into structured OpenAPI definitions. Use the OAS picker to select exactly which APIs to export for documentation, modeling, or integration with APIsec.ai's testing workflows.
7. APIsec.ai–powered API security analysis
API definitions discovered by BOLT can be analyzed using APIsec.ai's automated security engine, covering authentication and authorization issues, BOLA/IDOR, logic flaws, injection risks, misconfigurations, and complex multi-step attack paths.
8. One-click onboarding to APIsec.ai
From BOLT, send API definitions or captured request data to APIsec.ai to initiate onboarding or run automated test generation — including advanced scenarios that traditionally require manual effort or specialized expertise.
⸻
How It Works
1. Open a web application and launch APIsec BOLT from the Chrome or Firefox toolbar.
2. Start capture to automatically collect API traffic from your active browser tab.
3. Review discovered endpoints, real-time threat findings, and captured auth tokens.
4. Use the Manipulator to edit and replay requests, or export auto-generated OpenAPI specs.
5. Send APIs to APIsec.ai to onboard or run automated security analysis.
⸻
Non-intrusive and privacy-respecting by design
APIsec BOLT operates completely on the user's local machine. All traffic capture, API identification, threat detection, and OpenAPI generation occur locally within the browser extension.
BOLT does not intercept, modify, or block network traffic. It passively observes requests from the active browser tab solely for the purpose of API discovery, documentation, and security analysis.
Transmission of API data to APIsec.ai occurs only when the user explicitly initiates it. No data is sent externally without user action.
Reviews
Loading reviews...
Permissions (5)
Permissions
scriptingℹ Can inject scripts into web pages sidePanel storageℹ Can store data locally in your browser tabsℹ Can see your open tabs and their URLs webRequestℹ Can observe and analyze network traffic
Details
| Version | 2.0.6 |
| Updated | Mar 16, 2026 |
| Size | 489KiB |
| First Seen | Mar 22, 2026 |
More by developer
Forest: stay focused, be present
by developer
900K
★ 3.80
workflow
900K
★ 3.80
workflow
PasswordPocket
by developer
4K
★ 2.25
workflow
4K
★ 2.25
workflow
Gmail Auto BCC
by developer
2K
★ 3.67
workflow
2K
★ 3.67
workflow
Grandstream GRP Click2Dial
by developer
2K
★ 4.00
social
2K
★ 4.00
social
Grandstream Wave Click2Dial
by developer
1K
★ 1.33
social
1K
★ 1.33
social
Popular in privacy
uBlock Origin
by Raymond Hill (gorhill)
15M
★ 4.70
privacy
15M
★ 4.70
privacy
DuckDuckGo Search & Tracker Protection
by DuckDuckGo
4M
★ 4.24
privacy
4M
★ 4.24
privacy
Free VPN For Chrome - VPN Extension - Windscribe
by Windscribe
2M
★ 4.66
privacy
2M
★ 4.66
privacy
iboss Cloud Connector
by iboss
2M
★ 1.13
privacy
2M
★ 1.13
privacy
Ghostery Privacy AdBlocker
by Ghostery
2M
★ 4.64
privacy
2M
★ 4.64
privacy
Popular Extensions
Adobe Acrobat: PDF edit, convert, sign tools
by Adobe Inc.
330M
★ 4.40
workflow
330M
★ 4.40
workflow
Chrome Remote Desktop
by Chrome Remote Desktop Release Managers
38M
★ 3.14
workflow
38M
★ 3.14
workflow
Cisco Webex Extension
by cisco.chromestore
24M
★ 2.34
social
24M
★ 2.34
social
Kami for Google Chrome™
by Kami
17M
★ 4.56
education
17M
★ 4.56
education
Read&Write for Google Chrome™
by Texthelp
17M
★ 3.44
accessibility
17M
★ 3.44
accessibility