> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API security

> Discover API endpoints, import an OpenAPI specification, classify your inventory, and configure API traffic protection.

API security requires its Business add-on. Open **API security** for a protected domain to inspect the application's endpoint inventory and discovery results.

<Steps>
  <Step title="Build your inventory">Add an endpoint manually, import an OpenAPI JSON or YAML document, or configure discovery from traffic and a hosted specification.</Step>
  <Step title="Review scan results">Start a scan when needed and inspect its results. Review discovered paths, methods, tags, and groups before using the inventory operationally.</Step>
  <Step title="Classify endpoints">Edit endpoint metadata as your application evolves. Remove entries that no longer describe the application.</Step>
  <Step title="Configure API protection">Set the API traffic options and relevant URL patterns so protection handles API clients appropriately. Check real machine clients as well as browser traffic.</Step>
</Steps>

Import specifications that describe the protected application. Remove credentials and private examples before upload. An API inventory identifies exposed paths; your application must still enforce authentication and authorization.

## Automation

The API uses `/shield/domains/{domain_id}/api-paths` for inventory and `/shield/domains/{domain_id}/api-discovery/*` for discovery, settings, uploads, and scan results. Inventory listing accepts at most 10 records per request; use `limit` and `offset` until you have read the reported count. Other collections can have different limits.

Use the generated endpoint reference for the accepted JSON upload envelope, filters, and request fields. The specification upload endpoint accepts JSON; do not send an unwrapped multipart upload.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.