Four deterministic checks
- KEY-EXP-01 query-parameter keys or tokens
- HTTP-001 insecure server URLs
- AUTH-001 missing documented authentication
- KEY-EXP-02 undocumented static-key lifetime or rotation
OpenAPI Security
Speculynx scans OpenAPI 3.0 and 3.1 files locally, returns deterministic findings and explicit coverage, and keeps every conclusion scoped to the declared contract.
Free → Pro
Free works without a license or backend connection. Pro adds heuristic coverage, PDF export, and bounded live checks.
Review authorization, object access, rate limiting, data exposure, and other contract signals with explicit rule execution and coverage metadata.
Pro also adds PDF output and a bounded scan-live mode. It remains separate from Agent Security.
Output contract
JSON schema 1.0 reports executed, skipped, and non-evaluated rules; per-control status; findings; coverage; and verdict.
Install from PyPI and scan an OpenAPI 3.0 or 3.1 file without uploading it.