API targets

API assessments start in Workbench. This page is about your APIs as authorized targets — OpenAPI, Postman, or live endpoints. It is not a public Eresus API.

Add an API target

In the project, ingest only authorized API definitions:

  • OpenAPI / Swagger
  • Postman collections
  • Approved live endpoints

Strip embedded secrets before ingest. A collection that contains extra servers is not automatic authorization. Review every host before it becomes a target.

Ingest for OpenAPI, Postman, cURL, and approved endpoints
Ingest for OpenAPI, Postman, cURL, and approved endpoints

What happens after ingest

The API target uses the same Workbench path as any other assessment:

  • Modules and extensions
  • Authenticated identities
  • Findings
  • HTTP Records
  • OAST callbacks

See Projects and scans.

Need a workflow that is not documented here? Email contact@eresussec.com.