API targets
API assessments start in Workbench. This page is about your APIs as authorized targets — OpenAPI, Postman, or live endpoints. It is not a public Eresus API.
Add an API target
In the project, ingest only authorized API definitions:
- OpenAPI / Swagger
- Postman collections
- Approved live endpoints
Strip embedded secrets before ingest. A collection that contains extra servers is not automatic authorization. Review every host before it becomes a target.

What happens after ingest
The API target uses the same Workbench path as any other assessment:
- Modules and extensions
- Authenticated identities
- Findings
- HTTP Records
- OAST callbacks
See Projects and scans.
Related
Need a workflow that is not documented here? Email contact@eresussec.com.