4 min readUpdated

API Security & Discovery: Why You Can't Secure APIs You Don't Know About

There's a problem hiding in most organizations' API security programs: they're protecting the APIs they know about while leaving the ones they don't know about completely exposed.

Shadow APIs - endpoints created by developers for testing, legacy integrations that never got decommissioned, internal services accidentally exposed - are a significant and growing portion of most organizations' actual API surface. And because these APIs aren't in your API gateway or your WAF rules or your security documentation, they receive zero protection.

API security starts with API discovery. Everything else is downstream of that visibility.

The Shadow API Problem

How do shadow APIs appear? Several common paths:

  • Developer testing endpoints: Created for local development, deployed to staging, never removed from production
  • Legacy integrations: APIs built for an old system that was replaced, but the API endpoint remained
  • Third-party service callbacks: Webhook endpoints created for integrations that were later abandoned
  • Internal service exposure: Microservices meant to be internal-only that got accidentally assigned public routes
  • Documentation gaps: APIs that were built but never added to official API catalogs or documentation

Research consistently shows that organizations underestimate their actual API count by 40–60%. That gap represents unmonitored, untested, and unsecured attack surface.

The Shadow API Problem
The Shadow API Problem

What API Discovery Actually Involves

API discovery is the process of automatically finding all API endpoints in your environment, whether or not they're documented. Methods include:

Discovery MethodCoverageAccuracyEffort
Manual documentation reviewOnly known APIsHigh for knownVery high
API gateway inventoryGateway-routed APIs onlyHighMedium
Network traffic analysisAll active APIsHighLow (passive)
Code scanningAPIs defined in codeHighMedium
Dedups.ai agent-based discoveryAll exposed APIsHighLow

The most comprehensive approach combines network traffic analysis (which finds APIs based on actual usage) with code scanning (which finds APIs based on definitions, including rarely-used ones).

From Discovery to Security

Once you know what APIs exist, security work can begin in earnest. The security workflow for each discovered API involves:

Authentication and Authorization Review

Does the endpoint require authentication? Is authentication properly enforced at every method, or only at the resource level? Are authorization checks correct - does user A have access to user B's data?

This last point - authorization logic bugs - is consistently the most common critical API vulnerability. OWASP classifies this as Broken Object Level Authorization (BOLA) and Broken Function Level Authorization (BFLA), and they're notoriously hard to detect with automated tools alone.

Input Validation Testing

Does the API properly validate inputs? Common issues include:

  • SQL injection in query parameters
  • NoSQL injection in JSON bodies
  • Path traversal in file references
  • SSRF via URL parameters

Rate Limiting and Abuse Prevention

Can the API be abused through excessive requests? Many APIs, particularly internal ones, have no rate limiting because they were designed for trusted callers. When those APIs become exposed, the absence of rate limiting becomes a denial-of-service risk.

Sensitive Data Exposure

Does the API return more data than the client needs? Excessive data exposure - returning full database records when the client only needs a subset - is a common finding that often isn't noticed until it becomes a breach.

Dedups.ai's Approach to API Security & Discovery

Dedups.ai combines continuous API discovery with automated security testing to give engineering teams a current, accurate picture of their API surface and its security posture.

The platform identifies APIs across your AWS environment, tests them against OWASP API Security Top 10, and routes findings to the responsible team via Slack, Jira, or email. Because discovery is continuous, new APIs are picked up automatically - you don't have to remember to add them to a test scope.

Building a Sustainable API Security Program

The goal isn't a one-time audit - it's a continuous program that keeps pace with your API development velocity. Key elements:

  1. Continuous discovery that automatically finds new APIs as they're deployed
  2. Automated baseline testing that runs with each deployment
  3. Manual testing for critical and sensitive endpoints
  4. Monitoring that detects anomalous API usage in production
  5. Documentation that keeps your API catalog current
Building a Sustainable API Security Program
Building a Sustainable API Security Program

Ready to Get Started?

If you don't know how many APIs are running in your environment, you're not able to secure them effectively. Dedups.ai provides continuous API discovery and security testing that gives you complete visibility into your API surface - including the ones you didn't know you had.

Ready to get started?

Start securing your cloud infrastructure and optimising costs today.