WHAT IT CHECKS
API code, specifications such as OpenAPI files, and configuration, against 81 rules covering all ten OWASP API Security Top 10:2023 categories — object, property and function level authorization; authentication; resource consumption; sensitive business flows; server-side request forgery; security misconfiguration; inventory management; and unsafe consumption of third-party APIs.
WHERE THE RULES COME FROM
OWASP's official API Security Top 10:2023 category pages, plus one NIST document.
WHAT IT DOES NOT CHECK
- Not a penetration test. It reviews the code, specification and configuration; it does not call your API.
WHAT YOU GET BACK
- Each gap it finds, with the rule it fails and the source text that rule was taken from, quoted, so you can check it yourself.
- Replacement wording for each finding, and a corrected copy of your document to download.
- The pack's declared gaps, printed on every report, so you know what was not checked.
HOW TO RUN IT
In the browser. Sign in at https://vera.ink/verify, paste or upload the document, and choose this pack. New accounts start with 40 credits; a check costs 3 credits up to about 4,500 words.
From your AI assistant. vera.ink is an MCP server. Connect it to Claude Code or Cursor and ask your assistant to check a file against this pack: https://vera.ink/developers
GOOD TO KNOW
- vera.ink only reports findings it can tie to a rule in this pack, and quotes the source text so you can check it. Anything it can't tie to a rule is dropped from the report.
- It is a review aid, not legal advice or a certification. Read each finding before you act on it.
More checks: https://vera.ink/check