1
Build your inventory
Add an endpoint manually, import an OpenAPI JSON or YAML document, or configure discovery from traffic and a hosted specification.
2
Review scan results
Start a scan when needed and inspect its results. Review discovered paths, methods, tags, and groups before using the inventory operationally.
3
Classify endpoints
Edit endpoint metadata as your application evolves. Remove entries that no longer describe the application.
4
Configure API protection
Set the API traffic options and relevant URL patterns so protection handles API clients appropriately. Check real machine clients as well as browser traffic.
Automation
The API uses/shield/domains/{domain_id}/api-paths for inventory and /shield/domains/{domain_id}/api-discovery/* for discovery, settings, uploads, and scan results. Inventory listing accepts at most 10 records per request; use limit and offset until you have read the reported count. Other collections can have different limits.
Use the generated endpoint reference for the accepted JSON upload envelope, filters, and request fields. The specification upload endpoint accepts JSON; do not send an unwrapped multipart upload.