# API Security & Discovery: Why You Can't Secure APIs You Don't Know About

There's a problem hiding in most organizations' API security programs: they're protecting the APIs they know about while leaving the ones they don't know about completely exposed.

Shadow APIs - endpoints created by developers for testing, legacy integrations that never got decommissioned, internal services accidentally exposed - are a significant and growing portion of most organizations' actual API surface. And because these APIs aren't in your API gateway or your WAF rules or your security documentation, they receive zero protection.

API security starts with API discovery. Everything else is downstream of that visibility.

## The Shadow API Problem

How do shadow APIs appear? Several common paths:

- **Developer testing endpoints**: Created for local development, deployed to staging, never removed from production
- **Legacy integrations**: APIs built for an old system that was replaced, but the API endpoint remained
- **Third-party service callbacks**: Webhook endpoints created for integrations that were later abandoned
- **Internal service exposure**: Microservices meant to be internal-only that got accidentally assigned public routes
- **Documentation gaps**: APIs that were built but never added to official API catalogs or documentation

Research consistently shows that organizations underestimate their actual API count by 40–60%. That gap represents unmonitored, untested, and unsecured attack surface.

![The Shadow API Problem](/assets/blog-images/api-security-and-discovery-guide/api-discovery-problem.png)


## What API Discovery Actually Involves

API discovery is the process of automatically finding all API endpoints in your environment, whether or not they're documented. Methods include:

| Discovery Method | Coverage | Accuracy | Effort |
|---|---|---|---|
| Manual documentation review | Only known APIs | High for known | Very high |
| API gateway inventory | Gateway-routed APIs only | High | Medium |
| Network traffic analysis | All active APIs | High | Low (passive) |
| Code scanning | APIs defined in code | High | Medium |
| Dedups.ai agent-based discovery | All exposed APIs | High | Low |

The most comprehensive approach combines network traffic analysis (which finds APIs based on actual usage) with code scanning (which finds APIs based on definitions, including rarely-used ones).

## From Discovery to Security

Once you know what APIs exist, security work can begin in earnest. The security workflow for each discovered API involves:

### Authentication and Authorization Review

Does the endpoint require authentication? Is authentication properly enforced at every method, or only at the resource level? Are authorization checks correct - does user A have access to user B's data?

This last point - authorization logic bugs - is consistently the most common critical API vulnerability. OWASP classifies this as Broken Object Level Authorization (BOLA) and Broken Function Level Authorization (BFLA), and they're notoriously hard to detect with automated tools alone.

### Input Validation Testing

Does the API properly validate inputs? Common issues include:
- SQL injection in query parameters
- NoSQL injection in JSON bodies
- Path traversal in file references
- SSRF via URL parameters

### Rate Limiting and Abuse Prevention

Can the API be abused through excessive requests? Many APIs, particularly internal ones, have no rate limiting because they were designed for trusted callers. When those APIs become exposed, the absence of rate limiting becomes a denial-of-service risk.

### Sensitive Data Exposure

Does the API return more data than the client needs? Excessive data exposure - returning full database records when the client only needs a subset - is a common finding that often isn't noticed until it becomes a breach.

## Dedups.ai's Approach to API Security & Discovery

Dedups.ai combines continuous API discovery with automated security testing to give engineering teams a current, accurate picture of their API surface and its security posture.

The platform identifies APIs across your AWS environment, tests them against OWASP API Security Top 10, and routes findings to the responsible team via Slack, Jira, or email. Because discovery is continuous, new APIs are picked up automatically - you don't have to remember to add them to a test scope.

## Building a Sustainable API Security Program

The goal isn't a one-time audit - it's a continuous program that keeps pace with your API development velocity. Key elements:

1. **Continuous discovery** that automatically finds new APIs as they're deployed
2. **Automated baseline testing** that runs with each deployment
3. **Manual testing** for critical and sensitive endpoints
4. **Monitoring** that detects anomalous API usage in production
5. **Documentation** that keeps your API catalog current

![Building a Sustainable API Security Program](/assets/blog-images/api-security-and-discovery-guide/api-security-workflow.png)


## Ready to Get Started?

If you don't know how many APIs are running in your environment, you're not able to secure them effectively. [Dedups.ai](https://dedups.ai) provides continuous API discovery and security testing that gives you complete visibility into your API surface - including the ones you didn't know you had.
